Great Circle Associates Firewalls
(April 1995)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: UDP
From: paul @ hawksbill . sprintmrn . com (Paul Ferguson)
Date: Mon, 17 Apr 1995 08:52:44 -0500 (EST)
To: Brent @ GreatCircle . COM (Brent Chapman)
Cc: firewalls @ greatcircle . com
In-reply-to: <v02120b05abb8824b50b9 @ [158 . 152 . 139 . 213]> from "Brent Chapman" at Apr 17, 95 01:10:13 pm

Brent writes -

> >
> >I can see obvious needs for various UDP services across/through a
> >firewall, such as 53/UDP.
> 
> 
> Yes, you need to allow 53/UDP across the firewall, for DNS.  Other
> UDP-based services that you might want to allow are NTP (not much worse a
> problem than DNS, and dealt with in much the same way; see below) and maybe
> Archie (big problem, see below).
> 
> The main reason most well-constructed firewalls block UDP is because that's
> the only effective way to block access to RPC-based services like NFS and
> NIS/YP (which are RPC-over-UDP-based, but live on unpredictable UDP port
> numbers).
>


My point is that a statement, such as what Padgett mentioned, that 
there needs to be 'justification' for permitting UDP services through
a firewall needs further clarification. Each organization should
scrutinize their unique needs for _all_ services, including TCP.

Cheers,

- paul

 
_______________________________________________________________________________
Paul Ferguson                         
US Sprint                                          tel: 703.689.6828
Managed Network Engineering                   internet: paul @
 hawk .
 sprintmrn .
 com
Reston, Virginia  USA                             http://www.sprintmrn.com 


References:
  • Re: UDP
    From: Brent @ GreatCircle . COM (Brent Chapman)
Indexed By Date Previous: Re: Firewalls-Digest V4 #237
From: darrell @ expertg . com (DARRELL KNIGHT)
Next: ADVISORY 951072: Compromised system attacking network sites
From: "Andrew T. Robinson" <atr @ netmaine . com>
Indexed By Thread Previous: Re: UDP
From: Brent @ GreatCircle . COM (Brent Chapman)
Next: Re: UDP
From: Phil Trubey <phil @ netpart . com>

Google
 
Search Internet Search www.greatcircle.com