Re: Odd Ports Being Allowed

From: Tim D (mamoth_at_NOSPAMchartermi.net)
Date: 05/12/04


Date: Wed, 12 May 2004 14:29:43 -0400

Yep, I thought about this. I just wish the Web Proxy wouldn't be so
intrusive with the packets and just automatically detect and allow HTTP out.
Which I already knew it was doing, but I guess I wish ISA was able to lock
this down better. Perhaps a setting I was missing... but apparently not.

"Stefan Bako" <stefan@csc.ro> wrote in message
news:eaBp0xEOEHA.1276@TK2MSFTNGP11.phx.gbl...
> You can make a deny rule that denies access on the external sites on port
> 8080. I made this not to allow antiproxy's
> "Phillip Windell" <@.> wrote in message
> news:#asQgnEOEHA.2468@TK2MSFTNGP11.phx.gbl...
> > "Tim D" <mamoth@NOSPAMchartermi.net> wrote in message
> > news:uyzsABEOEHA.3380@TK2MSFTNGP11.phx.gbl...
> > > I would buy this argument if the protocol definition wasn't defined on
> > port
> > > 80. But, since it is, I would assume only traffic destined for port 80
> > would
> > > be allowed out.
> >
> > Well it's doing just what I said it would do. This is the same way it
> works
> > in the old Proxy2 as well. Exactly why it does that, I don't know.
Maybe
> > others will know.
> >
> > --
> >
> > Phillip Windell [MCP, MVP, CCNA]
> > www.wandtv.com
> >
> >
>
>



Relevant Pages

  • Re: [Full-disclosure] [inbox] Re: [ Capture Skype trafic ]
    ... conforming HTTP to travel along on port 80. ... you can't be a moron and have every other port under the sun open ... When Skype uses port 80, the protocol used is still Skype's ... if the SSL controls are installed these packets ...
    (Full-Disclosure)
  • RE: basic stateful inspection question
    ... What you are talking about is checking the packets if they are REAL http if ... http connections and point to somesort of CVP server that checks traffic ... This makes it more difficult to use port 80 through firewalls but if you can ...
    (Security-Basics)
  • Re: Dos attacks
    ... would include a certain amount of "probing" by other systems... ... and samples of the packets. ... A ping followed immediately by a port ... HTTP requests could be someone looking for unknown web sites, ...
    (comp.security.firewalls)
  • Re: Etherreal not capturing calls to localhost
    ... no packets are being seen or captured. ... I think the MS SOAP toolkit has a tracing utility where you set up a local proxy to which you direct your requests which are then traced and forwarded to the real address so you could e.g. set up that proxy for HTTP on port 8080 and have the normal web services for HTTP on port 80. ...
    (microsoft.public.dotnet.xml)
  • Re: Odd Ports Being Allowed
    ... HTTP is still HTTP no matter what port the destination is running ... The entry shows up in the Web Proxy log, ...
    (microsoft.public.isa)