If this hasn't been answered yet...
I beleive your fault is in how you think MS DNS works. Port 53 is
used for the initial connection/request, then (in the NT
implimentation) a dynamic port (greater than 1023) for the reply back
to the client.
| -----Original Message-----
| From: [EMAIL PROTECTED]
| [mailto:[EMAIL PROTECTED]]On Behalf Of Jason LaFlair
| Sent: Thursday, December 02, 1999 2:07 PM
| To: [EMAIL PROTECTED]
| Subject: Re: Web-FTP-DNS-Frontpage
|
|
| LET ME GIVE YOU SOME BACKGROUND!!!!
|
| ALL I'm Looking for is the below question.. THAT'S IT!!!
|
| I've got other security means (firewall) protecting this
| server... I just
| want to add this as another 'backup' source of security...
|
| I just need an answer to the below question... not
| consultants telling me
| what I'm doing wrong when they have NO clue what the big
| picture even it.
|
| Sorry.. had to vent.. got TOO many replies telling me what I'm
doing
| wrong.... and it's NOTHING but not knowing the answer to the
below
| question..
|
| Jason.
|
|
| ----- Original Message -----
| From: "Jason LaFlair" <[EMAIL PROTECTED]>
| To: <[EMAIL PROTECTED]>
| Sent: Thursday, December 02, 1999 9:56 AM
| Subject: Web-FTP-DNS-Frontpage
|
|
| > This is not a true firewall question but this is the BEST
| place to ask
| it...
| >
| > I've got an NT Server v4.0 SP5 running IIS 4.0. From
| this server I want
| to
| > run Web, FTP and DNS Services. I also want to use the
| security for the
| > Ethernet adapter to restrict the ports.
| >
| > The problems I'm running into are for DNS.. if I set TCP,
| UDP and IP to
| ALL
| > it works.. but when I try to restrict it fails.
| >
| > My current settings are:
| > TCP: 21, 53, 80, 111
| > UDP: ALL
| > IP: 6
| >
| > I have tried this:
| > TCP: 21, 42, 53, 80, 101, 111, 135, 137, 138, 139, 530
| > UDP: ALL
| > IP: 6
| > but it still fails.
| >
| > What I'm looking for are the ports for all 3 (TCP, UDP
| and IP) so I can
| run
| > my Web, FTP and DNS servers on this NT box.
| >
| > Thanx.
| >
| > Jason LaFlair
| > [EMAIL PROTECTED]
| >
| > -
| > [To unsubscribe, send mail to [EMAIL PROTECTED] with
| > "unsubscribe firewalls" in the body of the message.]
|
| -
| [To unsubscribe, send mail to [EMAIL PROTECTED] with
| "unsubscribe firewalls" in the body of the message.]
-
[To unsubscribe, send mail to [EMAIL PROTECTED] with
"unsubscribe firewalls" in the body of the message.]