Great Circle Associates Firewalls
(August 1997)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: PPTP & FW-1
From: Dick_Wall @ stratus . com
Date: Tue, 5 Aug 97 13:57:31 -0400
To: evyncke @ cisco . com, firewalls-owner @ GreatCircle . COM
Cc: bc17684 @ 90 . deere . com, Beall_Linda/na2 @ na2 . stratus . com, Eckler_Richard/na2 @ na2 . stratus . com, Firewalls @ GreatCircle . COM, fw-1-mailinglist @ us . checkpoint . com
In-reply-to: <3 . 0 . 32 . 19970804135929 . 006f8da8 @ brussels . cisco . com>

> PPTP is using:
> - a modified GRE tunnel which lays directly on the top
> of IP with protocol (I do not have right now the number of the
> protocol but check in /etc/protocols for the right number)
> - a TCP control session to port 5678 (on the PPTP 'server') which
> is by the way a funny number ;-)

Is it really 5678 ??  I was told that the port was really 1723.  And
that if I wanted to prevent my users from establishing PPTP sessions ..
block outbound (towards the Internet) requests to TCP port 1723.  Did I
get some bad info ?

Dick

> 
> Also beware that PPTP is probably useful for you but do not
> trust too much its security... 
> 
> -eric
> 
> At 11:45 1/08/97 -0500, Bertrum Carroll wrote:
> >I'm attempting to setup a FW-1 filter to support PPTP.
> >I'm using FW-1 3.0a on Solaris.
> >
> >PPTP is not defined, how do I seutp a fitler just for PPTP not all
IP?
> >
> >Thanks In Advance
> >Bert Carroll
> >
> Eric Vyncke      
> Technical Consultant               Cisco Systems Belgium SA/NV
> Phone:  +32-2-778.4677             Fax:    +32-2-778.4300
> E-mail: evyncke @
 cisco .
 com          Mobile: +32-75-312.458
> 



References:
Indexed By Date Previous: Re: Mail bombing made legal...
From: Remco van de Meent <remco @ oloon . student . utwente . nl>
Next: NT SMTP/BIND risks - int
From: mcwilkin <mcwilkin @ twcable . com>
Indexed By Thread Previous: Re: PPTP & FW-1
From: Eric Vyncke <evyncke @ cisco . com>
Next: Re: PPTP & FW-1
From: snorthc @ nswc . navy . mil (Stephen Northcutt - CD2S)

Google
 
Search Internet Search www.greatcircle.com