Restricting source port across sites

Restricting source port across sites

Secure Home | Search | About
 Networking Firewalls    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Restricting source port across sites Lordy 05-11-2006
Posted by Lordy on May 11, 2006, 4:56 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Hi,

I have to deal with a firewall policy where they *insist* on only allowing
comminucation to AND FROM specific ports across sites. This also includes
the infamous DCOM port 135. Which is ironic, bacause I'm beginning to
think this cant be done. (Which is probably the intention!)

I know that RPC can be configured to only use a certain port range
( http://support.microsoft.com/default.aspx?scid=kb;en-us;Q300083 )

But AIUI, this range only applies to the temporary server port that is
created by the RPC port mapper on the destination machine.
It does not apply to the ehpemeral address range on the client machine.
So the from port could still be any port in the ephemeral range.

A bodge (that might really break the client box) would be to set
\HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\MaxUserPorts
to a low value. (Shame there is no MinUserPorts setting)

And possibly reduce TcpTimesWaitDelay to 10 seconds or so, so ports get
freed up quciker??

Lordy


Similar ThreadsPosted
Multiple Source IP port numbers October 26, 2005, 3:51 am
Port Translation based on Source Address November 7, 2004, 11:09 pm
PIX 525: Restricting www access September 18, 2005, 11:11 am
Help with restricting access to VPN WRT54G August 6, 2007, 3:41 pm
Thoughts about restricting outgoing communication December 12, 2006, 3:07 pm
Another source other than KRNIC? November 9, 2005, 4:39 pm
GREAT SOURCE TO SHARE! March 13, 2005, 8:36 am
open source web proxy suggestions ? September 27, 2007, 9:57 pm
Setting up VPN (Netscreen) with different source (trust) IP October 24, 2007, 5:08 pm
where can I get the simple personal firewall source code December 30, 2005, 4:48 am

The site map in XML format XML site map

Contact Us | Privacy Policy