12.07.2015 Views

WSM User Guide - WatchGuard Technologies

WSM User Guide - WatchGuard Technologies

WSM User Guide - WatchGuard Technologies

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Blocking PortsBlocking PortsYou can block the ports that you know can be used to attack your network. This stops specified externalnetwork services. When you block a port, you override all the service configurations.You can block a port because:• Blocking ports protects your most sensitive services. The feature helps protect you from errors inyour Firebox® configuration.• Probes against sensitive services can make independent log entries.With the default configuration, the Firebox blocks some destination ports. This gives a basic configurationthat you usually do not have to change. It blocks TCP and UDP packets for these ports:X Window System (ports 6000-6005)The X Window System (or X-Windows) client connection is not encrypted and is dangerous touse on the Internet.X Font Server (port 7100)Many versions of X-Windows operate X Font Servers. The X Font Servers operate as the superuseron some hosts.NFS (port 2049)NFS (Network File System) is a frequently used TCP/IP service where many users use the samefiles on a network. But, the new versions have important authentication and security problems.To supply NFS on the Internet can be very dangerous.NoteThe portmapper frequently uses the port 2049 for NFS. If you use NFS, make sure that NFS uses the port2049 on all your systems.rlogin, rsh, rcp (ports 513, 514)These services give remote access to other computers. They are a security risk and manyattackers probe for these services.RPC portmapper (port 111)The RPC Services use port 111 to find which ports a given RPC server uses. The RPC services areeasy to attack through the Internet.port 8000Many vendors use this port, and there are many security problems related to it.port 1The TCPmux service uses Port 1, but not frequently. You can block it to make it more difficult forthe tools that examine ports.port 0This port is always blocked by the Firebox. You cannot add this port to the Blocked Ports list.You cannot allow traffic on port 0 through the Firebox.NoteIf you must allow traffic through for the types of software applications that use recommended blockedports, we recommend that you allow the traffic only through an IPSec VPN tunnel or get access to theport using ssh for more security.142 <strong>WatchGuard</strong> System Manager

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!