Re: Firewall best practices
"Darden, Patrick S." <[email protected]>
| Newsgroups | gmane.comp.security.firewalls.wizards |
|---|---|
| Message-ID | <[email protected]> |
Good point. I fight against EVERYTHING. :-) However, if a connection has distinct endpoints, and uses an encrypted protocol (ssh, ssl, ipsec) then I fight with less energy. We have a VMZ here which helps--a sandbox that we put vendor supplied systems that do not follow our best practices. We firewall them out of the network, allow only limited access, and stipulate the vendor is responsible for security for their system. I think you have to seek the truth of whether the service is needed or just desired, and then balance security vs. utility. --p -----Original Message----- From: [email protected] [mailto:[email protected]] On Behalf Of Morty Sent: Friday, April 16, 2010 12:41 AM To: Firewall Wizards Security Mailing List Subject: Re: [fw-wiz] Firewall best practices On Wed, Apr 14, 2010 at 09:10:36AM -0400, Jason Lewis wrote: > The point of my question was if you're forced into a position to open > everything, what ports *should* you always block and why. Or less controversially, suppose you *do* have a default deny, and you get requests to allow point-to-point dataflows (inbound or outbound) and/or completely open select ports outbound. Which ports/services should you fight back on or recommend alternatives? As a general rule, I fight back on protocols that do unencrypted auth and/or are intended for local LAN use and/or are very attractive to malware authors. Examples: FTP, telnet, SMTP, portmap, 135, 137, 138, 139, 445, 1433, NFS, IRC. If you have IDS, your perspective might change because crypto-enabled ports cause you to lose insight. - Morty _______________________________________________ firewall-wizards mailing list [email protected] https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards