11.07.2015 Views

WatchGuard Firebox System 7.0 User Guide

WatchGuard Firebox System 7.0 User Guide

WatchGuard Firebox System 7.0 User Guide

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Blocking PortsBy default, the <strong>Firebox</strong> blocks several destination ports.This measure provides convenient defaults which do notnormally require changing. Typically, the following servicesshould be blocked:X Window <strong>System</strong> (ports 6000-6063)The X Window <strong>System</strong> (or X-Windows) has severaldistinct security problems that make it a liability onthe Internet. Although several authenticationschemes are available at the X server level, the mostcommon ones are easily defeated by aknowledgeable attacker. If an attacker can connectto an X server, he or she can easily record allkeystrokes typed at the workstation, collectingpasswords and other sensitive information. Worse,such intrusions can be difficult or impossible todetect by all but the most knowledgeable users.The first X Window server is always on port 6000.If you have an X server with multiple displays,each new display uses an additional port numberafter 6000, up to 6063 for a maximum of 64 displayson a given host.X Font Server (port 7100)Many versions of X-Windows support font servers.Font servers are complex programs that run as thesuper-user on some hosts. As such, it is best toexplicitly disable access to X font servers.NFS (port 2049)NFS (Network File <strong>System</strong>) is a popular TCP/IPservice for providing shared file systems over anetwork. However, current versions have seriousauthentication and security problems which makeproviding NFS service over the Internet verydangerous.NOTEPort 2049 is not assigned to NFS; however, in practice, thisis the most common port used for NFS. The port assigned forNFS is assigned by the portmapper. If you’re using NFS, it<strong>User</strong> <strong>Guide</strong> 189

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!