>I was also working under this assumption, any allow "ANY" outgoing 
>traffic. So, basically you're saying I can block all outgoing traffic with 
>no ill effects to web/email/etc?
>
>Is there a reason to do this? Nobody actually sits at the server and surfs 
>the internet or anything.

If you do block outgoing traffic, you'll need to [1] Make sure that any 
legitimate outgoing connections are allowed (IE outgoing connections to the 
SMTP port on remote mailservers and outgoing DNS requests needed for mail 
delivery), and [2] That your firewall (or router) doesn't require you do 
something special (a special line to all established TCP/IP connections, or 
allowing outgoing traffic on all ports >1024) as per the other E-mails in 
this thread.

The reason why you might want to do this is to help minimize problems if 
the server is compromised.  For example, blocking all outgoing traffic 
except SMTP/DNS traffic would mean that if the server was compromised, a 
trojan horse on the server would have to communicate via SMTP or DNS ports 
if sending outgoing traffic, making the hacker's job more difficult.

                                                    -Scott
---
Declude: Anti-virus, Anti-spam and Anti-hijacking solutions for 
IMail.  http://www.declude.com

---
[This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)]


Please visit http://www.ipswitch.com/support/mailing-lists.html 
to be removed from this list.

An Archive of this list is available at:
http://www.mail-archive.com/imail_forum%40list.ipswitch.com/

Please visit the Knowledge Base for answers to frequently asked
questions:  http://www.ipswitch.com/support/IMail/

Reply via email to