Re: TCP/IP filtering and opening DNS

Tech-Archive recommends: Speed Up your PC by fixing your registry

From: Kevin D. Goodknecht [MVP] (admin_at_nospam.LSAOL.COM)
Date: 03/05/04


Date: Fri, 5 Mar 2004 08:13:49 -0600

In news:40488379$1_6@corp.newsgroups.com,
Eric Vanderveer <kalindine@speednetllc.com> posted a question
Then Kevin replied below:
> I am having some problems with TCP/IP filtering and DNS with my
> network cards. I allow ports that I need to remote into my servers
> and they work great but when I allow port 53 (tCP and UDP) I can't
> get to any webpages. Typing in the IP address works like a charm so I
> know its something with DNS. Anyone have an idea what else I need to
> do?

You also need to open ports above 1024 for outgoing connections.
Packet filtering on the NIC closes ports in and out, when applications make
outgoing connections they use ports 1024 and higher.

-- 
Best regards,
Kevin D4 Dad Goodknecht Sr. [MVP]
Hope This Helps
============================
-- 
When responding to posts, please "Reply to Group"  via your
newsreader so that others may learn and benefit from your issue.
To respond directly to me remove the nospam. from my email.
==========================================
 http://www.lonestaramerica.com/
==========================================
Use Outlook Express?... Get OE_Quotefix:
It will strip signature out and more
 http://home.in.tum.de/~jain/software/oe-quotefix/
==========================================
Keep a back up of your OE settings and folders with
OEBackup:
 http://www.oehelp.com/OEBackup/Default.aspx
==========================================


Relevant Pages

  • RE: TCP/IP Filtering problem on W2KAS
    ... The problem is that if you are listing ports that are 'allowed' and you ... don't list every dynamic port used by a client to access the DNS ... "Using IPSec to Lock Down a Server": ... I find using the IPSec filters MUCH more useful then the TCP/IP Filtering. ...
    (Focus-Microsoft)
  • Re: TCP/IP Filtering
    ... > interesting thing in reference to using TCP/IP Filtering ... > on a W2000 client. ... I Allowed only Ports 25 Mail, ... > DNS, 67&68 DHCP, and 80&443 Internet. ...
    (microsoft.public.win2000.security)
  • TCP/IP Filtering
    ... interesting thing in reference to using TCP/IP Filtering ... I Allowed only Ports 25 Mail, ... DNS, 67&68 DHCP, and 80&443 Internet. ... Well I found out that DNS returns to a client on a port ...
    (microsoft.public.win2000.security)
  • Re: Is This Normal DNS Behavior on a Server2003 SP2 Domain Controller
    ... Protection against the Microsoft DNS Cache Poisoning Vulnerability ... These response or service ports, are used by all Windows communications. ... How to reserve a range of ephemeral ports on a computer that is running Windows Server 2003 or Windows 2000 Server ...
    (microsoft.public.windows.server.dns)
  • Re: Issue with port blocking on public DNS server
    ... I am talking about the "Destination Ports" in the "Responses to local DNS ... names (other then the domain names in my own DNS server) on the servers. ... Filtering outbound requests on port 53 FROM the DNS to the Internet ...
    (microsoft.public.windows.server.dns)