you can limit destination = 53 > -----Original Message----- > From: [EMAIL PROTECTED] > [mailto:[EMAIL PROTECTED] Behalf Of Jhon Wong > Sent: Saturday, September 27, 2003 11:37 PM > To: [EMAIL PROTECTED] > Subject: [xmail] Re: question about RDNS > > > > Hi Rob, > For Dns,source port could be anything? > Then I cann't limit anything on UDP. > Is that secure? > > Jhon > > > > > > DNS uses tcp&udp port 53 (not 42) as a destination and the source is > usually > > also 53, but could be anything. > > > > Rob :-) > > > > > -----Original Message----- > > > From: [EMAIL PROTECTED] > > > [mailto:[EMAIL PROTECTED] Behalf Of jhon wong > > > Sent: Saturday, September 27, 2003 12:12 PM > > > To: [EMAIL PROTECTED] > > > Subject: [xmail] Re: question about RDNS > > > > > > > > > Francis, > > > Thanks for your guide. I am not familer with firewall setting. > > > So I asking you more question here.If my server is only used > > > as POP3,SMTP,WWW server, and additionally terminal service. > > > I plan to set up Input Filter as following: > > > protocol: TCP(destination port: 25,110,80,3389) > > > TCP(established) > > > UDP(source port : 42)for dns > > > > > > Is that OK? and NetBIOS will not exist,right? > > > > > > > > > > > > > > - option 3 : 'BETTER' solution : install Routing and RAS > (included in > > > > windows 2k server) (minimum the routing part) > > > > To install routing and ras, launch 'Routing and Remote > access' console > > > > manager from administrative tools > > > > Select your server, right clic it and select > 'install/configure rras' > > > > Choose 'routing' only > > > > When it become installed and running, in the rras mmc console, go to > > > > 'General' in 'IP routing', you will see your connexions > > > > Right click the internet connexion > > > > In the 'General' tab you have two button : Input filters > and Output = > > > > filters > > > > Select if you want 'allow all except' or 'deny all except' > (it is here > = > > > > the > > > > 'basic' functionnality, you just can't mix allow and deny, > but if you > = > > > > put > > > > good rules here, you have a perfect firewall at final setup!!) > > > > > > > > Even if i currently have a separate firewall running, i > allway used = > > > > this > > > > feature to protect my exposed w2k systems (do you fully trust you = > > > > firewall ? > > > > is your firewall allways secure ? or don't have bugs ...) > > > > > > > > Francis > > > > > > > > > > > > > > > > > > > > - > > > To unsubscribe from this list: send the line "unsubscribe xmail" in > > > the body of a message to [EMAIL PROTECTED] > > > For general help: send the line "help" in the body of a message to > > > [EMAIL PROTECTED] > > > > > > > > > > - > > To unsubscribe from this list: send the line "unsubscribe xmail" in > > the body of a message to [EMAIL PROTECTED] > > For general help: send the line "help" in the body of a message to > > [EMAIL PROTECTED] > > > > > - > To unsubscribe from this list: send the line "unsubscribe xmail" in > the body of a message to [EMAIL PROTECTED] > For general help: send the line "help" in the body of a message to > [EMAIL PROTECTED] > >
- To unsubscribe from this list: send the line "unsubscribe xmail" in the body of a message to [EMAIL PROTECTED] For general help: send the line "help" in the body of a message to [EMAIL PROTECTED]
