Re: Simple IPSEC filter

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance

From: dlbrum (dlbrum_at_discussions.microsoft.com)
Date: 03/17/05


Date: Thu, 17 Mar 2005 10:47:05 -0800

I misread your post. The reason I am wary of your suggested filter is that I
don't want any host anywhere to be able to come in thru any port... Just
25...

?

If I allow one machine in without restricting to TCP and port 25, it's fine.
 As soon as I restrict that same filter to TCP and port 25, no can do...
sigh...

"Steven L Umbach" wrote:

> Try a rule with a permit filter action that includes a mirrored filter entry
> for destination address - my IP, source address - any, protocol - TCP,
> destination port 25, source port - any. --- Steve
>
>
> "dlbrum" <dlbrum@discussions.microsoft.com> wrote in message
> news:CDADE320-B506-4D18-8CF3-C13E0D0F907A@microsoft.com...
> > I've got a policy that is successful in restricting access to a server by
> > IP
> > addresses and subnets. No protocol restrictions.
> >
> > Now I'd like to open the machine to accept SMTP port 25 traffic from the
> > universe.
> >
> > A simple filter like the address filters above that adds port 25 TCP
> > mirrored + "permit" doesn't seem to do the trick. It seems logical that
> > port/protocol would be more "specific", but the filter won't permit
> > machines
> > outside of my "permit" group to see port 25.
> >
> > Appreciate any ideas ..
> >
> > Dave, U. of FL Gators...
>
>
>



Relevant Pages

  • Re: What can I do about breakin attempts?
    ... address ranges) where you might actually want to connect. ... By restricting the allowed IP addresses, ... an uncommon port number, ... mind as the quickest solution. ...
    (comp.os.linux.security)
  • Re: Port forwarding based on source IP?
    ... > Can you specify the remote port in remote desktop? ... Each of the ports could have a port rule that's ... I can specify the port with a registry hack. ... So the question becomes which routers support "port rules" (restricting ...
    (comp.security.firewalls)