On Mon, 2003-06-16 at 14:32, rikona wrote:
> Hello Technoslick,
> 
> Sunday, June 15, 2003, 7:31:07 AM, you wrote:
> 
> T> I have a Linksys router/gateway that has the ability to dynamically
> T> open ports and port ranges when a certain executable is requesting
> T> to do so from a network client. This has worked very well from
> T> Windows clients using NetMeeting, ICQ or MSN Messenger for video
> T> conferencing and chat sessions, respectively.
> 
> It might be that it only works with Netmeeting or other pgms that
> specifically use that capability.

No, thankfully. It just has to be an executable that shows itself in
calling for services through ports that need to be opened. This is a
very limited feature in that it only allows for ten designations.
NetMeeting takes up three (if I include the ILS/ULS servers) which means
that I lose the opportunity to open ports for two other applications.
Once ten designations have been made, that's it. On the other hand, if
your network has several clients that would use ICQ, whether one or 100
were on, the ports would open for any client running ICQ. It is a neat
feature. I don't believe it is program specific, but it may be that the
programs have to H.323 compliant. I would think LICQ is to work with
other IM's that are. Wouldn't you?

> 
> I was VERY interested in this idea because it opens up an entirely
> different level of protection for the comps on the local net. Without
> this, it is necessary to have a separate *app-aware* firewall on each
> computer.
> 

Exactly. If you have ICQ (continuing the example) run at different times
over the network by different clients, you would need to go into DMZ
just to keep up with the requests. If you do that, it can't be a
firewall anymore. 

To provide software firewalls on each client that would do this as
needed, you still would have to put the router's firewall into DMZ or
nothing gets through the firewall barrier to the Web.

> I found this on the net, as a starter:
> 
> --------
> 
> When Microsoft developed NetMeeting 3.0 they chose to use the existing
> h.323 video conferencing protocol. This protocol happens to be
> completely incompatible with standard NAT(network address translation)
> - the technology used for most internet sharing devices.
> 
> Unlike most TCP/IP applications, NetMeeting uses DYNAMIC PORTS instead
> of STATIC PORTS. That means that each NetMeeting connection is
> somewhat different than the last. For instance, the HTTP web site
> application uses port 80. NetMeeting can use any of over 60,000
> different ports. Putting a web server behind a firewall means opening
> a single small hole. Putting a NetMeeting computer behind a firewall
> means opening over 60,000 ports - a security nightmare.

Which is why running a NetMeeting server locally would be something yo
would want to run entirely off on its own network. Most of us wouldn't
have a need for a NetMeeting server. Generally speaking, you are going
to open ports 1024 through 65,535 for H.323 communications entailing
video, sound and chat capability with NetMeeting. That's a whole lot of
holes! Other clients can shoe-horn in with fewer ports, but from what
few I have played with and what have reports I've read, NetMeeting is
*the* top performer --- because it uses such a wide band of ports to
carry such heavily laden data at a reasonable bandwidth. Shut down the
ports and you bottleneck video and audio conferencing quality and
performance. The other choices are not pleasant, either.

Gnomemeeting is suppose to be a NetMeeting clone/client. It's got to be
as much a security issue in Linux as in the Windows environment.

> 
> A few hardware manufacturers have taken it on themselves to actually
> provide H.323 compatibility. This is not an easy task since the router
> must search each incoming packet for signs that it might be a
> netmeeting packet. This is a whole lot more work than a router
> normally does and may actually be a weak point in the firewall.

True, but something's got to do it. Better "it" than "me". 

> 
> So - it does not seem to be generally useful, and introduced a new
> batch of security problems. Too bad. It sounded good. :-)

I haven't given up on this, just tabling it for a while, at least until
I can regroup for another attack. ;0)

T


Want to buy your Pack or Services from MandrakeSoft? 
Go to http://www.mandrakestore.com

Reply via email to