WSM User Guide - WatchGuard Technologies

WSM User Guide - WatchGuard Technologies WSM User Guide - WatchGuard Technologies

watchguard.com
from watchguard.com More from this publisher
12.07.2015 Views

Packet Filter PoliciesCharacteristics• Internet Protocol(s): TCP• Port Number(s): 1755, 80NetMeetingNetMeeting is a product developed by Microsoft Corporation that enables groups to teleconferenceacross the Internet. It is included with Microsoft’s Internet Explorer web browser. This policy is based onthe H.323 protocol and does not filter for dangerous content. It does not support QoS or rsvp protocol,and it does not support NAT.Characteristics• Internet Protocol(s): TCP• Port Number(s): 1720, 389NFSThe Network File System (NFS) protocol is a client server software application created by Sun Microsystemsto allow all network users to get access to shared files kept on computers of different types.Characteristics• Internet Protocol(s): TCP and UDP• Port Number(s): TCP 2049, UDP 2049NNTPNetwork News Transfer Protocol (NNTP) is used to transmit Usenet news articles.The best procedure to use NNTP is to set internal hosts to internal news servers and external hosts tonews feeds. In most conditions NNTP must be enabled in two directions. If you operate a public newsfeed,you must allow NNTP connections from all external hosts. WatchGuard cannot make sure thatthese packets were sent from the correct location.You can configure the Firebox to add the source IP address to the Blocked Sites list when an incomingNNTP connection is denied. All of the usual log options can be used with NNTP.Characteristics• Internet Protocol(s): TCP• Port Number(s): 119NTPNetwork Time Protocol (NTP) is a protocol built on TCP/IP that controls local timekeeping. It synchronizescomputer clocks with other clocks located on the Internet.Characteristics• Internet Protocol(s): UDP and TCP388 WatchGuard System Manager

Packet Filter Policies• Port Number(s): TCP 123 and UDP 123OSPFOpen Shortest Path First (OSPF) is a routing protocol developed for IP networks based on the link-statealgorithm. OSPF is quickly replacing the use of RIP on the Internet because it gives smaller, more frequentupdates to routing tables and makes networks more stable.Characteristics• Internet Protocol(s): OSPF• Protocol Number(s): 89pcAnywherepcAnywhere is a software application used to get remote access to Windows computers. To enable thisprotocol, add the PCAnywhere policy. Then, allow access from the hosts on the Internet that must getaccess to internal pcAnywhere servers, and to the internal pcAnywhere servers.pcAnywhere is not a very secure policy and can put network security at risk, because it allows trafficthrough the firewall without authentication. Also, your pcAnywhere server can receive denial-of-serviceattacks. We recommend that you use VPN options to give more security.Characteristics• Internet Protocol(s): UDP and TCP• Port Number(s): UDP 22, UDP 5632, TCP 5631, TCP 65301pingYou can use ping to confirm if a host can be found and is operating on the network. To find DOS-basedor Windows-based traceroute packets, configure a ping policy.Outgoing ping is a good tool for troubleshooting. We do not recommend you enable ping connectionsincoming to your trusted network.Characteristics• Internet Protocol(s): ICMP• Protocol Number(s): 1POP2 and POP3POP2 and POP3 (Post Office Protocol) are e-mail transport protocols, usually used to get a user’s e-mailfrom a POP server.Characteristics• Internet Protocol(s): TCP• Port Number(s): 109 (POP2), and 110 (POP3)User Guide 389

Packet Filter PoliciesCharacteristics• Internet Protocol(s): TCP• Port Number(s): 1755, 80NetMeetingNetMeeting is a product developed by Microsoft Corporation that enables groups to teleconferenceacross the Internet. It is included with Microsoft’s Internet Explorer web browser. This policy is based onthe H.323 protocol and does not filter for dangerous content. It does not support QoS or rsvp protocol,and it does not support NAT.Characteristics• Internet Protocol(s): TCP• Port Number(s): 1720, 389NFSThe Network File System (NFS) protocol is a client server software application created by Sun Microsystemsto allow all network users to get access to shared files kept on computers of different types.Characteristics• Internet Protocol(s): TCP and UDP• Port Number(s): TCP 2049, UDP 2049NNTPNetwork News Transfer Protocol (NNTP) is used to transmit Usenet news articles.The best procedure to use NNTP is to set internal hosts to internal news servers and external hosts tonews feeds. In most conditions NNTP must be enabled in two directions. If you operate a public newsfeed,you must allow NNTP connections from all external hosts. <strong>WatchGuard</strong> cannot make sure thatthese packets were sent from the correct location.You can configure the Firebox to add the source IP address to the Blocked Sites list when an incomingNNTP connection is denied. All of the usual log options can be used with NNTP.Characteristics• Internet Protocol(s): TCP• Port Number(s): 119NTPNetwork Time Protocol (NTP) is a protocol built on TCP/IP that controls local timekeeping. It synchronizescomputer clocks with other clocks located on the Internet.Characteristics• Internet Protocol(s): UDP and TCP388 <strong>WatchGuard</strong> System Manager

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!