RE: Port Blocking in Firewall

Juergen Quittek <[email protected]> Mon, 06 Dec 2004 12:21:57 +0100
Newsgroups gmane.ietf.midcom
Message-ID <2147483647.1102335717@[10.1.1.171]>
Hi Stewart,

--On 06.12.2004 18:53 Uhr +0800 Stewart Pu wrote:

> As Tom pointed out, the natural behavior/principle of firewall is to block
> everything. Administrators will determine which port to open, depending on
> what kind services is needed (e.g. FTP, HTTP, etc.)
>
> My understanding is even with MIDCOM deployed, this is a manual process,
> right? Does MIDCOM have the capability to communicate with firewall to open
> the wanted port? e.g. To open the 5060 port if SIP application is needed?

Yes and no.

Yes, because it is possible opening a pinhole for port 5060 dynamically
with MIDCOM.  MIDCOM was specifically designed for this kind of actions.

However, MIDCOM was not designed for static configuration of a firewall.
Typically, a firewall would restrict the maximum lifetime of a pinhole that
is granted.  But if you want to be able to receive SIP signaling, you might
want to have it configured statically (at least if you use an incoming SIP
proxy).  In this case using MIDCOM for such a static configuration might not
be ideal, because you would have to extend the lifetime for your 5060 pinhole
regularly.

Still, extending the lifetime regularly (and using MIDCOM for this purpose)
may be preferable if you want to maintain a high level of security and/or if
you want to enable and disable SIP signaling to terminals.


Thanks,

    Juergen
-- 
Juergen Quittek        [email protected]       Tel: +49 6221 90511-15
NEC Europe Ltd.,       Network Laboratories        Fax: +49 6221 90511-55
Kurfuersten-Anlage 36, 69115 Heidelberg, Germany   http://www.netlab.nec.de


> Regards
> Stewart
>
> -----Original Message-----
> From: [email protected] [mailto:[email protected]] On Behalf Of
> Taylor, Tom-PT [CAR:5N00:EXCH]
> Sent: Monday, December 06, 2004 6:33 PM
> To: Pyda Srisuresh
> Cc: [email protected]
> Subject: Re: [midcom] Port Blocking in Firewall
>
> That's right.  Basically the attitude was that administration would block
> everything by default, and MIDCOM would enable exceptions (subject to policy
> at
> the server).
>
> Pyda Srisuresh wrote:
>> My understanding is that the WG decided to go with specifyign just the
>> permitted ports, not the blocked ports, during the semantics discussion.
>>
>> regards,
>> suresh
>> --- Tom Green <[email protected]> wrote:
>>
>>
>>> Hi,
>>>
>>> I am kind of new to MidCom. RFC 3303(MidCom
>>> Architecture and Framework)says that MidCom protocol
>>> will enable us to open select ports in the firewall.
>>> Is it possible to block some ports using this
>>> framework?
>>>
>>> Thanks,
>>> TG
>>>
>>>
>>>		
>>> __________________________________
>>> Do you Yahoo!?
>>> Take Yahoo! Mail with you! Get it on your mobile phone.
>>> http://mobile.yahoo.com/maildemo
>>>
>>> _______________________________________________
>>> midcom mailing list
>>> [email protected]
>>> https://www1.ietf.org/mailman/listinfo/midcom
>>>
>>
>>
>>
>> =====
>>
>>
>> _______________________________________________
>> midcom mailing list
>> [email protected]
>> https://www1.ietf.org/mailman/listinfo/midcom
>>
>>
>
> --
> Tom Taylor
> Carrier VoIP Standards Development
> Nortel Networks
> Phone +1 613 763 1496  (ESN 393-1496)
> E-mail: [email protected]
>
> _______________________________________________
> midcom mailing list
> [email protected]
> https://www1.ietf.org/mailman/listinfo/midcom
>
>
> _______________________________________________
> midcom mailing list
> [email protected]
> https://www1.ietf.org/mailman/listinfo/midcom