you can limit destination = 53

> -----Original Message-----
> From: [EMAIL PROTECTED]
> [mailto:[EMAIL PROTECTED] Behalf Of Jhon Wong
> Sent: Saturday, September 27, 2003 11:37 PM
> To: [EMAIL PROTECTED]
> Subject: [xmail] Re: question about RDNS
>
>
>
> Hi Rob,
>     For Dns,source port could be anything?
> Then I cann't limit anything on UDP.
> Is that secure?
>
>        Jhon
>
>
> >
> > DNS uses tcp&udp port 53 (not 42) as a destination and the source is
> usually
> > also 53, but could be anything.
> >
> > Rob :-)
> >
> > > -----Original Message-----
> > > From: [EMAIL PROTECTED]
> > > [mailto:[EMAIL PROTECTED] Behalf Of jhon wong
> > > Sent: Saturday, September 27, 2003 12:12 PM
> > > To: [EMAIL PROTECTED]
> > > Subject: [xmail] Re: question about RDNS
> > >
> > >
> > > Francis,
> > >     Thanks for your guide. I am not familer with firewall setting.
> > > So I asking you more question here.If my server is only used
> > > as POP3,SMTP,WWW server, and additionally terminal service.
> > > I plan to set up Input Filter as following:
> > >     protocol: TCP(destination port: 25,110,80,3389)
> > >                   TCP(established)
> > >                   UDP(source port : 42)for dns
> > >
> > >    Is that OK? and NetBIOS will not exist,right?
> > >
> > >
> > > >
> > > > - option 3 : 'BETTER' solution : install Routing and RAS
> (included in
> > > > windows 2k server) (minimum the routing part)
> > > > To install routing and ras, launch 'Routing and Remote
> access' console
> > > > manager from administrative tools
> > > > Select your server, right clic it and select
> 'install/configure rras'
> > > > Choose 'routing' only
> > > > When it become installed and running, in the rras mmc console, go to
> > > > 'General' in 'IP routing', you will see your connexions
> > > > Right click the internet connexion
> > > > In the 'General' tab you have two button : Input filters
> and Output =
> > > > filters
> > > > Select if you want 'allow all except' or 'deny all except'
> (it is here
> =
> > > > the
> > > > 'basic' functionnality, you just can't mix allow and deny,
> but if you
> =
> > > > put
> > > > good rules here, you have a perfect firewall at final setup!!)
> > > >
> > > > Even if i currently have a separate firewall running, i
> allway used =
> > > > this
> > > > feature to protect my exposed w2k systems (do you fully trust you =
> > > > firewall ?
> > > > is your firewall allways secure ? or don't have bugs ...)
> > > >
> > > > Francis
> > > >
> > > >
> > >
> > >
> > >
> > > -
> > > To unsubscribe from this list: send the line "unsubscribe xmail" in
> > > the body of a message to [EMAIL PROTECTED]
> > > For general help: send the line "help" in the body of a message to
> > > [EMAIL PROTECTED]
> > >
> > >
> >
> > -
> > To unsubscribe from this list: send the line "unsubscribe xmail" in
> > the body of a message to [EMAIL PROTECTED]
> > For general help: send the line "help" in the body of a message to
> > [EMAIL PROTECTED]
> >
>
>
> -
> To unsubscribe from this list: send the line "unsubscribe xmail" in
> the body of a message to [EMAIL PROTECTED]
> For general help: send the line "help" in the body of a message to
> [EMAIL PROTECTED]
>
>

-
To unsubscribe from this list: send the line "unsubscribe xmail" in
the body of a message to [EMAIL PROTECTED]
For general help: send the line "help" in the body of a message to
[EMAIL PROTECTED]

Reply via email to