Great Circle Associates Firewalls
(February 1997)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re : irc and firewalls / site security
From: Mark Gillett <mgillett @ sghms . ac . uk>
Date: Fri, 21 Feb 1997 11:55:12 PST
To: firewalls @ GreatCircle . COM

It seems to me that IRC is both undesirable in a commercial sense, the 
corporation firewalling it's network is unlikely to want IRC 'style' 
recreational use anyway.  If they do and you need to set up a 
'secure-ish' IRC access method - the mIRC client supports SSL 
connections, which may help.  Personally I think it best that it be 
kept out.... It took a while to get together the details of which 
ports were used by IRC servers and I hope the following list is 
exhaustive.... anyone who knows of any others, I would much appreciate 
the information. (we block IRC even before the firewall - at the 
router).
[CISCO]
! deny's IRC by filtering packets on IRC ports.
    deny   tcp any any eq 6661 
    deny   tcp any any eq 6662 
    deny   tcp any any eq 6663 
    deny   tcp any any eq 6664 
    deny   tcp any any eq 6665 
    deny   tcp any any eq 6666 
    deny   tcp any any eq 6667
    deny   tcp any any eq 6668 
    deny   tcp any any eq 6669 
    deny   tcp any any eq 6670 
    deny   tcp any any eq 7000 
    deny   tcp any any eq 124
    deny   tcp any any eq 529
    deny   tcp any any eq 6671
    deny   tcp any any eq 6673
    deny   tcp any any eq 6675
! end deny IRC 

All the best,

<Mark>

================================================================
Mark Gillett, Computer Unit, St. Georges Hospital Medical School
----------------------------------------------------------------
Contrary to popular belief, Unix is user friendly. It just 
happens to be very selective about who it decides to make 
friends with.
----------------------------------------------------------------
e-mail : mgillett @
 sghms .
 ac .
 uk
web :    http://www.sghms.ac.uk
================================================================



Indexed By Date Previous: Re: CNET story on Microsoft defending ActiveX today
From: Pierre . Beyssac @ hsc . fr (Pierre Beyssac)
Next: stack bounds checking
From: Michael Richardson <mcr @ sandelman . ottawa . on . ca>
Indexed By Thread Previous: Re: Raptor Eagel - redirecting incoming connections
From: Matt Wallace <mwallace @ netcom . com>
Next: stack bounds checking
From: Michael Richardson <mcr @ sandelman . ottawa . on . ca>

Google
 
Search Internet Search www.greatcircle.com