IIS Outbound Ports

From: Dominic Marsat (djmarsatAThotmail.com)
Date: 03/09/04


Date: Tue, 9 Mar 2004 10:46:47 -0000

I'm running IIS on a windows 2000 server

The server is behind a firewall which only
allows incoming connections on port 80
(TCP & UDP) and blocks all others

Users log onto the server using integrated
windows authentication, anonymous access
is disabled.

Problem:

If all outgoing ports, except port 80 (TCP
& UDP) are closed users cannot access the
site. Entries appear in the firewall logs but
not in the website logs (i.e. their IP address).

Temp Solution:

Allow outgoing UDP ports in the range
1000-2000, although these connections
never appear in the firewall logs, which
made identifying the problem extremely
difficult + users still report intermittent
connection problems.

Is this IIS related or due to the firewall
(Netgear DG834)?

Can anyone provide a complete list of
ports required by IIS for this
configuration?



Relevant Pages

  • Re: Port 135
    ... The patch doesn't disable DCOM / RPC, so connections can still be made. ... That's why you need a firewall. ... the patch is not the thing to control ... control over your TCP/IP ports and services, ...
    (microsoft.public.security)
  • Re: Got Active Ports, now what?
    ... have services running and ports open does not in ANY way shape or form mean ... vulnerabilities and links to plenty of other ... Why do I need 23 connections to the ... > You should get a 'Application' Filtering Firewall for your XP box. ...
    (comp.security.firewalls)
  • Re: File sharing
    ... Instead of creating exceptions for individual ports for FPS I suggest that you try Group Policy and configuring the exemption for file and print sharing and probably the remote administration exemption. ... If there are do domain level Group Policies being applied to these computers currently for Windows Firewall, which you could verify by running rsop.msc on the client computer, you could try using local Group Policy to see if it does what you want. ... So then I went back and put in a custom setting to accept connections on the local subnet plus connections from my subnet, ...
    (microsoft.public.windowsxp.security_admin)
  • Re: On passwords, securtiy and real -sweat, blook and tears- life
    ... given that all ports are closed to external contact through a physical allbeit consumer oriented firewall, just means I am safe for port-scanners. ... connections reduces the risk a lot. ... you can boot in single user mode and change the password. ...
    (Fedora)
  • Re: Open Ports on a hardware firewall
    ... If you have the ports open, e.g. people are allowed to initiate connections ... isn't about detecting queso, but more about tracking past data ... you're telling the firewall that every incoming packet ...
    (comp.security.misc)