Re: MSN messenger audio connections & XP SP2?

From: Jonathan Kay [MVP] (msnewsreplies_at_jonathankay.com)
Date: 06/28/04


Date: Mon, 28 Jun 2004 12:44:56 -0400

Hi Andy,

The Windows XP firewall (current and SP2) handle inbound connections only -- outgoing
connections are not blocked.

I'm not 100% sure what you mean here, so I'll simply explain how the current firewall does it
and then how the SP2 firewall can.

Current Firewall:
1. Either side of a conversation initiates an Audio conversation and accepts it
2. Messenger sends API call to firewall to open necessary port for audio conversation
3. Messenger sends information on current IP and audio port to connect to the other contact
4. Incoming connection from contact to the specified port
5. After conversation is complete, API call to remove the open port

and we're done. Also keep in mind that Windows Messenger will also open some ports when it
starts (MSN Messenger does not).

The SP2 firewall is basically the same, with the exception that the SP2 firewall will allow
you to unblock all inbound to Messenger, therefore not requiring the individual ports to be
opened.
____________________________________________
Jonathan Kay
Microsoft MVP - Windows Messenger/MSN Messenger
Associate Expert
http://www.microsoft.com/windowsxp/expertzone/
Messenger Resources - http://messenger.jonathankay.com
All posts unless otherwise specified are (c) 2004 Jonathan Kay.
You *must* contact me for redistribution rights.

"Andy Weller" <getstuff@dsl.pipex.com> wrote in message news:2k9q9oF18s5fuU1@uni-berlin.de...
> Hi Jonathan
> Thanks for the screenshot - is this how firewall is configured to permit
> OUTBOUND connections from your PC by specified programs? (ie similar to
> Zonealarm "trusting" specified programs). Or is this screen somehow
> related to the program INBOUND access attempts that the firewall will let
> through?
>
> My puzzle is still that for inbound protection, the new XP firewall will
> surely be working in "stealth" mode - ie the PC and ports are not visible to
> any inbound intruder or other traffic. If so, then I'm still puzzled how
> another MSN messenger audio session will ever "see" the target PC to connect
> to - unless the firewall lets all intruders "see" the ports and the PC.
>
> Sorry if I'm not very good at explaining this security stuff, but I am still
> unsure how it can work!
>
> Cheers
>
> Andy
> ----------------------------------------------------------------------------
> -------
>
> If so, I the issue i was trying to explore is the way that the firewall
> blocks INBOUND access attempts - which is where MSN messenger
>
> "Jonathan Kay [MVP]" <msnewsreplies@jonathankay.com> wrote in message
> news:ubqop6LXEHA.2636@TK2MSFTNGP10.phx.gbl...
>> Hi Andy,
>>
>> Actually the current Windows XP Firewall supports Universal Plug and Play
> (UPnP) and will
>> automatically open the necessary ports for Messenger. The SP2 firewall
> also supports UPnP,
>> but in SP2, this is even expanded further by allowing you to be specific
> about which
>> applications can use the Internet connection (in this case MSN Messenger
> 6.2).
>>
>> Just for fun, I took a screenshot of what it looks like (and for reference
> purposes, it put
>> "MSN Messenger 6.2" there by itself; another new feature of SP2 and MSN
> Messenger 6.2):
>> http://messenger.jonathankay.com/screens/sp2firewall.png
>> ____________________________________________
>> Jonathan Kay
>> Microsoft MVP - Windows Messenger/MSN Messenger
>> Associate Expert
>> http://www.microsoft.com/windowsxp/expertzone/
>> Messenger Resources - http://messenger.jonathankay.com
>> All posts unless otherwise specified are (c) 2004 Jonathan Kay.
>> You *must* contact me for redistribution rights.
>>
>> "Andy Weller" <getstuff@dsl.pipex.com> wrote in message
> news:2k8qcbF18p1f4U1@uni-berlin.de...
>> > Jonathan
>> >
>> > Great news! I was hoping to use the new XP SP2 firewall, and that it
> would
>> > allow me to connect both Audio & webcam via MSN messenger to keep in
> touch
>> > with my daughter at university.
>> >
>> > Does this news mean that MS have somehow overcome the audio issue in
>> > http://messenger.msn.com/Help/Issues.aspx (April 2004) which says:
>> >
>> > "To ensure we deliver the best audio technology for computer-to-computer
> or
>> > computer-to-phone communications from MSN Messenger, we have made
> technical
>> > enhancements. This means you will only be able to use Messenger version
> 4.5
>> > or higher for these features if:
>> > a.. You are not behind a firewall or
>> > b.. You are behind a Universal Plug and Play (UPnP) firewall or
>> > c.. You are using a UPnP-enabled Network Address Translation (NAT)
> device"
>> >
>> > Maybe an obvious question, but I'd expected the XP firewall would have
>> > stopped MSN messenger audio connections - how does it allow MSN
> messenger
>> > audio through without compromising security?
>> >
>> > Cheers
>> >
>> > Andy
>> >
>
>



Relevant Pages

  • VideoConf Nightmare
    ... Firewall Router so you can read the instructions on How ... >instructions (from your reply to "audio on messenger" on ... >But as stated, all appeared to work, however, the UPnP ... More on firewall and port opening can be ...
    (microsoft.public.windowsxp.messenger)
  • Re: Application Popup Messenger Service SPAM
    ... NO NO NO. Use a firewall. ... It is not a bad idea to also disable the Messenger service, ... Messenger Service pop-ups] on my computer? ... Using a firewall and disabling NetBIOS is still strongly recommended. ...
    (microsoft.public.win2000.security)
  • Re: Windows Firewall Blocks my ability to connect to an FTP site
    ... I'm using SP2 ... port 21 and did the steps the the KB Article. ... with the firewall off works fine. ... The Command-line FTP reports Unknown Error Number. ...
    (microsoft.public.windowsxp.security_admin)
  • Re: WMI RPC Server not available
    ... I have WinXP SP2 clients. ... configured using a GPO to enable the Firewall and set up a few port and ... Since installing SP2, this now does not work for XP SP2 machines, but does ...
    (microsoft.public.windowsxp.wmi)
  • Re: Port 25 closing?
    ... > connections to our mail server via port 25. ... I can log onto the firewall, ... > after installing SP2. ...
    (Fedora)