Re: TCP - UDP Ports used in file sharing & associated anomolies

From: Scott Harding - MS MVP (scrockel_at_**NO_SPAM**hotmail.com)
Date: 03/31/04


Date: Wed, 31 Mar 2004 09:57:23 -0700

Ok, well that makes more sense. I would think a router would be a much
better way to stop this broadcast traffic than a firewall though and you
wouldn't have to deal with the ports. Can you jsut install a Windows box as
a router to toure the traffic? As far as the port 80 issue this is certainly
NOT used for authentication and not sure how that fits in. Could be a Linux
thing for some reason, also how do these people try to connect? Through a
web interface? from the run line? through Network Places?

-- 
Scott Harding
MCSE, MCSA, A+, Network+
Microsoft MVP - Windows NT Server
"J. McKee" <anonymous@discussions.microsoft.com> wrote in message
news:3CD46EEC-0FF1-42BD-AE02-03F85637221A@microsoft.com...
> The firewall isn't for security reasons... everything is on the same
physical network in the same physical building. Here is the purpose of the
firewall...
>
> It segregates a hardware lab from the production network. The reason for
this is b/c the hardware being developed emits a broadcast UDP packet every
fraction of a second... as you can see I'd rather keep this garbage off of
the production network. Now imagine that you have 6 or 7 running at the same
time... it brings things to a virtual halt.
>
> I suppose I could just drop all broadcast packets, but these anomolies
have me interested and I'd like to figure this out...


Relevant Pages

  • Re: How are they broadcasting through my proxy server?
    ... both connecting to our router. ... (including the firewall). ... Notice on my first post that I showed you guys 3 packets comming from ... out last broadcast IP address. ...
    (comp.security.firewalls)
  • SunScreen and Broadcasts
    ... firewall and have had a lot of frustration trying to get help ... through Sun's support. ... interface on the backup network isn't even connected. ... traffic to the broadcast address of the internal ...
    (Focus-SUN)
  • TCP Connections to a Broadcast Address on BSD-Based Systems
    ... BSD-based TCP/IP code has a bug with respect to creating TCP ... TCP implementation works correctly and do not block broadcast ... firewall host or gateway, the potential for exploitation is probably ...
    (Bugtraq)
  • Re: iptables DNAT --to-destination problem
    ... > No sane router will forward a general broadcast. ... >> The generated package can not be logged by the Firewall, ... After that includes the firewall doesnt logg FORWARD packages too :-( ... The computer B can't sniff the Broadcast message on eth1, ...
    (comp.os.linux.security)
  • Re: Firewall Attack by ip with broadcast adress!!
    ... > I think it's the broadcast adress. ... the packet, the firewall software you use, if any, and any messages the ... firewall is telling you about what sort of attack this supposedly is. ...
    (microsoft.public.win2000.security)

Loading