Help - Search - Members - Calendar
Full Version: Default ports blocked for the V3?
Gladiator Security Forum > SoftSphere Technologies Support Forums > DefenseWall HIPS
Ilya Rabinovich
Hi everybody!

Just finished with ports blocking function (outbound protection is already done and tested). What are the initial ports need top be closed with firewall by default? I assume, 445 and 139 must be there any case, what else?
takaki
TCP 135、139、445、593、1025
UDP 135、137、138、445

andro
If one follows the program WWDC, then the ports 135,137,138, 5000 should also be closed.
Ilya Rabinovich
139? NetBios is quite important thing if I remember it correctly...
andro
NetBIOS allows users to obtain general access to files or devices.
mossman
One question Ilya, apologies if it has been answered before, but will it be possible to turn off this firewall function? I already use Outpost Firewall and I know that you should not have two firewalls active.
Buddel
QUOTE (mossman @ Jul 15 2009, 05:54 PM) *
One question Ilya, apologies if it has been answered before, but will it be possible to turn off this firewall function? I already use Outpost Firewall and I know that you should not have two firewalls active.

Good question. I would also like to be able to turn this firewall off. I do hope this will be possible because I already have a firewall.
Creer
Ilya for example this is a restricted ports list from OA Free:

http://www.tallemu.com/webhelp3/FWAdv.html

Edit:
You can also ask Stem from Wilders he is FW expert.
Ilya Rabinovich
QUOTE (mossman @ Jul 15 2009, 03:54 PM) *
One question Ilya, apologies if it has been answered before, but will it be possible to turn off this firewall function? I already use Outpost Firewall and I know that you should not have two firewalls active.

1. If you already have a firewall, teher is no need to buy or use Personal Firewall version. HIPS version will be still available and will not increase its cost.
2. Yes, both INbound and Outbound filters can be switched off separately.
Ilya Rabinovich
QUOTE (Creer @ Jul 15 2009, 06:00 PM) *
You can also ask Stem from Wilders he is FW expert.

Thanks, Creer, just sent a message.
Chachazz
Ilya, we can drop third-party firewall altogether when (DW firewall component) tested, proven, and final release? Is it to be used with Windows firewall?

edit: changed 'posts' to 'ports' in the topic.
mossman
QUOTE (Ilya Rabinovich @ Jul 15 2009, 08:08 PM) *
QUOTE (mossman @ Jul 15 2009, 03:54 PM) *
One question Ilya, apologies if it has been answered before, but will it be possible to turn off this firewall function? I already use Outpost Firewall and I know that you should not have two firewalls active.

1. If you already have a firewall, teher is no need to buy or use Personal Firewall version. HIPS version will be still available and will not increase its cost.
2. Yes, both INbound and Outbound filters can be switched off separately.
Thanks for both answers. :)
Ilya Rabinovich
QUOTE (Chachazz @ Jul 15 2009, 11:07 PM) *
Ilya, we can drop third-party firewall altogether when (DW firewall component) tested, proven, and final release? Is it to be used with Windows firewall?

1. I believe- yes. But you can check the software by yourself and make a clear decision.
2. There is no need to switch of built-in Windows firewall.
Trespasser
This upcoming version will be terrific in XP. Also, I thought you were just concentrating on outbound protect since XP, Vista, and Win 7 have inbound by default. Removing inbound protection would lighten the resource demand on DefenseWall, wouldn't it?

Later...
ktango
Hi Ilya Rabinovich,

NetBios ports such as TCP 135, TCP & UDP 137, TCP & UDP 138, TCP 139 and TCP & UDP 445 are important for local area network (LAN) file sharing. All of them should not be exposed to the Internet. You can get information of those ports from shields up !!

http://www.grc.com/port_135.htm
http://www.grc.com/port_138.htm
http://www.grc.com/port_139.htm
http://www.grc.com/port_445.htm
Ilya Rabinovich
QUOTE (Trespasser @ Jul 17 2009, 04:55 AM) *
This upcoming version will be terrific in XP. Also, I thought you were just concentrating on outbound protect since XP, Vista, and Win 7 have inbound by default. Removing inbound protection would lighten the resource demand on DefenseWall, wouldn't it?

1. Unfortunately, inbound protection with XP-W7 is implemented very interesting way. If you are in the Ethernet environment, it unlocks 139 and 445 ports (printer/file sharing and SMB). So, if your computer is locating within Ethernet network (so-called home networks), it may be vulnerable. See Kido, for instance.
2. Switching Inbound off will not dramatically improve the performance as it is requires to switch it on and off on the fly. So, it's implemented like a simple data field (on/off).
Threedog
Ilya, it might be an idea to have an option to configure it for "direct to internet" or "home lan option" that way people who have a lan setup behind router and do internal file sharing between the computers could easily configure it for that situation. Likewise, anyone connecting directly to the internet could easily configure it to block all ports as file sharing would not be needed and having those ports exposed would not be a good thing.
Ilya Rabinovich
I was thinking about such the profiles too. But I have no idea about ports should be with that profiles.
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.
Invision Power Board © 2001-2009 Invision Power Services, Inc.