Re: outgoing firewall rules

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance

From: Bernard (qbernard_at_hotmail.com.discuss)
Date: 12/13/04


Date: Mon, 13 Dec 2004 12:09:48 +0800

for ftp you need inbound 21 and outbound 20 (active mode)
in passive mode, you need a lot more, google 'passiveportrange'

you can test your connection without firewall to see if it make any
differences.
if it is a standalone hardware box and not handling 'thousand' of policy, I
don't think it will affect overall performance of your website.

-- 
Regards,
Bernard Cheah
http://www.tryiis.com/
http://support.microsoft.com/
http://www.msmvps.com/bernard/
"PR" <pr@nospam.com> wrote in message 
news:ej7EAOM4EHA.1596@tk2msftngp13.phx.gbl...
> Hi all, we recently moved our servers to a different hosting provider. The
> original provider's firewall allowed all outgoing traffic for the servers.
> The new provider only allows certain protocols (80, 443, 21, 25, 3389, 
> DNS)
> etc. We have begun seeing slower performance after moving and I am 
> thinking
> do these firewall restrictions have anything to do with it? My web boxes 
> run
> the following services:-
>
> HTTP, HTTPS, FTP, SMTP
>
> What are the min outgoing traffic rules reqd for these services?
>
> thanks!
>
> 


Relevant Pages

  • Re: FTP error using a MAC
    ... Yes, you are using active mode, but the firewall/NAT can't take care of it ... behind a firewall, you then told me to change to active mode? ... In active mode the FTP client connects from a random unprivileged port N ...
    (microsoft.public.inetserver.iis.ftp)
  • Re: FTP server behind a PF firewall (including NAT)
    ... > Thank you, but I have a working PF configuration for FTP clients, both ... > for active and passive mode. ... > this firewall) that allows both active mode and passive mode clients. ... > Active-mode transfers are the easiest (again, allow connections to all ...
    (comp.unix.bsd.freebsd.misc)
  • Re: Passive Mode issue
    ... in the windows firewall and the network firewall with the same results. ... and the ftp site is bound to a specific public IP. ... The server will timeout from all users trying passive mode. ... passive port range for IIS and opened those ports in the firewall, ...
    (microsoft.public.inetserver.iis.ftp)
  • Re: [fw-wiz] Active to Passive FTP translator?
    ... The threat is that the firewall protecting the client needs to allow ... the attacker is allowed to connect to the sql server. ... For firewalls that do not reassemble the ftp control channel TCP stream, ... clients to speak active mode, ...
    (Firewall-Wizards)
  • FC3: no route to host with enabled firewall
    ... i've problem with my firewall. ... of my outgoing connections are filtered. ... ftp> ls ... 227 Entering Passive Mode ...
    (Fedora)