Re: Question regarding firewalls
- From: "Gregg Hill" <bogus@xxxxxxxxxxx>
- Date: Mon, 9 Jul 2007 10:16:54 -0700
The whole point of lock-down is to STOP the gmail, hotmail, yahoo mail, etc
crap that has no business in a business.
I use OE to post. Does it still require 119?
Gregg Hill
"kj [SBS MVP]" <KevinJ.SBS@xxxxxxxxxxxxxxxxxx> wrote in message
news:uTB43GkwHHA.4572@xxxxxxxxxxxxxxxxxxxxxxx
Lanwench [MVP - Exchange] wrote:
Gregg Hill <bogus@xxxxxxxxxxx> wrote:
Hello!
In an SBS domain, what firewall ports are really needed for most
businesses to have full functionality? I would like to have the
maximum lock-down I can achieve with normal network and Internet
functionality.
I can think of the following, in numerical order:
Inbound ports forwarded in firewall/router:
25 to SBS
443 to SBS
3389 to a 2000 or 2003 terminal server
4125 to SBS
Maximum outbound ports allowed:
20 and 21 for downloads
25 to send mail (preferably only from SBS server's IP)
53 for DNS lookups
80 for web browsing
110 if they use POP3 on external server
123 for NTP
143 if they use IMAP on external server
443 for secure web browsing
2002 if servers are managed with LogMeIn
I cannot think of others that would be needed for normal web
browsing, email access, etc. Do AV apps such as Trend Micro CSM use
different ports to get their updates?
Did I miss any ports?
Thank you for your time!
Gregg Hill
In addition to the other replies-
Your clients should need only HTTP and HTTPS outbound, most likely.
Your firewall should be configured with a deny all by default for the
IP address range used for your client workstations, and 80 and 443
outbound only. Your users shouldn't be connecting to external POP,
IMAP, FTP sites, etc., generally.
Your server needs more outbound access - your 'maximum' list is fine
in general, although I'd exclude 110, 2002, 143. I don't know why
you'd need LogMeIn.....
119 to post to this newgroup! <g>
Greg,
465/995 (outbound) POP-S for gmail or wait till the users call.
--
/kj
.
- Follow-Ups:
- Re: Question regarding firewalls
- From: kj [SBS MVP]
- Re: Question regarding firewalls
- From: Cris Hanna [SBS-MVP]
- Re: Question regarding firewalls
- References:
- Question regarding firewalls
- From: Gregg Hill
- Re: Question regarding firewalls
- From: Lanwench [MVP - Exchange]
- Re: Question regarding firewalls
- From: kj [SBS MVP]
- Question regarding firewalls
- Prev by Date: Re: How to run a script when users logon due VPN
- Next by Date: Re: SBS 2003. WON'T RECEIVE INCOMING FAXES. PLS HELP
- Previous by thread: Re: Question regarding firewalls
- Next by thread: Re: Question regarding firewalls
- Index(es):
Relevant Pages
|
Loading