TO UNSUBSCRIBE: email "unsubscribe issforum" in the body of your message to
[EMAIL PROTECTED]  Contact [EMAIL PROTECTED] for help with any problems!
----------------------------------------------------------------------------

Hi Sunny,
If I understand your question correctly, you have a RealSecure Network
Engine inside your firewall and want to kill a conversation where one of the
participants is outside the firewall and the other participant is inside the
firewall (otherwise the traffic would never cross the segment where the
RealSecure engine is listening).

The answer is that you don't have to open any additional ports through the
firewall. When we "kill" a connection, we send a TCP RESET packet to both
participants in the conversation. We use the same ports that they are using
to communicate, or they would ignore the RESET. The firewall must already be
allowing communication on those ports to pass, or the original conversation
wouldn't be happening...make sense? Also, keep in mind that often, different
ports will be used for each new connection and the ports used for the RESETS
will change accordingly.

The only time that I can think of that you need to open specific ports
through a firewall is if the RealSecure console is inside a firewall and the
engine is outside...then you open ports for them to communicate. The default
ports for this are in the documentation, and you can change them if you'd
like.
Hope this helps,
sheila

-----Original Message-----
From: Sunny Leung [mailto:[EMAIL PROTECTED]]
Sent: Tuesday, January 26, 1999 9:21 PM
To: [EMAIL PROTECTED]
Subject: Realsecure and Firewall



TO UNSUBSCRIBE: email "unsubscribe issforum" in the body of your message to
[EMAIL PROTECTED]  Contact [EMAIL PROTECTED] for help with any
problems!
----------------------------------------------------------------------------

Dear All,
After enabling the "KILL" function on ISS Realsecure which is behide a
Firewall(Check Point), which port(s) should i open on Firewall to allow the
"KILL" traffic pass through Firewall ?

Regards,
Sunny

Reply via email to