Solved

Firewall/Port information

Posted on 2003-12-09
4
1,654 Views
Last Modified: 2013-11-16
Hi,
I believe I have an okay understanding of how port numbers work. I just bought a router and firewall software. I need to know how do I configure the firewall, in other words, how do I know which local ports to block to avoid intruders. Thanks for any help on this.
0
Comment
Question by:bduffy120
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
4 Comments
 
LVL 79

Accepted Solution

by:
lrmoore earned 250 total points
ID: 9905462
Most software firewalls block all incoming traffic by default, unless you've specifically requested it. If you're behind a router that is doing NAT (Network address translation), then it is providing a first "shield" to make you virtually invisible to start with. Depending on what all you have on your local LAN, and the software firewall that you have, you might have a checkbox "allow local LAN access" or "allow netbios"
0
 
LVL 1

Expert Comment

by:NeilDavis
ID: 9905464
Its easier to block all ports and them open up only the ones you need for mail and internet access.  Your router also may have port filtering which is worth a look.

80 - HTTP - Internet, 110 - pop3 - email etc.  All port numbers are listed here:

http://www.iana.org/assignments/port-numbers

0
 
LVL 41

Expert Comment

by:stevenlewis
ID: 9905935
go to www.grc.com and test your sheilds and scan your ports
chances are they are already blocked, and you may be back here asking how to open some (for games, etc)
0
 
LVL 25

Expert Comment

by:mikeleebrla
ID: 9912665
inless you are running a www or mail server, do not open port 80 or 110... you will still be able to get to the web and get your mail with these ports closed since your firewall sees that these connections were started from the "inside" and not the "outside" so it will allow them to come thru.   If you do open these ports you will have to do port forwarding to direct them to a particular machine on the inside since what is actually going on is PAT (port address translation).
0

Featured Post

Free NetCrunch network monitor licenses!

Only on Experts-Exchange: Sign-up for a free-trial and we'll send you your permanent license!

Here is what you get: 30 Nodes | Unlimited Sensors | No Time Restrictions | Absolutely FREE!

Act now. This offer ends July 14, 2017.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

If you're not part of the solution, you're part of the problem.   Tips on how to secure IoT devices, even the dumbest ones, so they can't be used as part of a DDoS botnet.  Use PRTG Network Monitor as one of the building blocks, to detect unusual…
This article is a collection of issues that people face from time to time and possible solutions to those issues. I hope you enjoy reading it.
Michael from AdRem Software outlines event notifications and Automatic Corrective Actions in network monitoring. Automatic Corrective Actions are scripts, which can automatically run upon discovery of a certain undesirable condition in your network.…
In this brief tutorial Pawel from AdRem Software explains how you can quickly find out which services are running on your network, or what are the IP addresses of servers responsible for each service. Software used is freeware NetCrunch Tools (https…

688 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question