Solved

basic firewall setup query

Posted on 2004-09-02
3
124 Views
Last Modified: 2013-11-16
hi there.

semi-quick question.

I'm working on a network that has an adsl connection that all the office pc's (being on a private IP network) NAT through the router/modem to get to the outside world.

It's got a firewall capability on it, disabled at the moment, allowing anything and everything through.

I've been in control of a firewall with two different offices before but that was about 4 yrs ago and I'm somewhat rusty on my firewall theory at the moment.

i know it's asking a bit, but can anyone gimme a basic set of firewall rules to allow users on the 192.168.0.* ip range to access anything in the outside world (192.168.0.0/32 etc) and a couple of basic rules to allow one ip address from the outside world to access an ip addy on the port 80 protocol on the private network?

(I know it's fairly easy and I'm fairly sure I could manage it but I'd just like to make sure I know what i'm doing first, cant practice on anything handy,y'see.)

thanks very much

Daryn
0
Comment
Question by:daryn
  • 2
3 Comments
 
LVL 11

Expert Comment

by:billwharton
ID: 11962821
Well, you probably only want to allow your internal users to the following protocols on the Internet.
Port 80, 443 for web traffic
Port 21 for FTP


If your users use telnet, then open up port 23 and if they also use external SMTP servers, open up port 25.

Now, if you want to allow Internet users access to an inside server on port 80, you would need to create a static NAT entry and then put in an access list allowing traffic on port 80 to the inside server.

If you need further help configuring your firewall, please state the brand and model number.
0
 

Author Comment

by:daryn
ID: 11971371
it's a dlink dsl-504t adsl modem router. I understand/remember the concepts of port opening, standard ports etc but the actual notation etc, the /32 subnet mask marking etc, are eluding me right now.
0
 
LVL 11

Accepted Solution

by:
billwharton earned 250 total points
ID: 11971394
well, if your network is 192.168.0.0 then your subnet mask would be 255.255.255.0

However, if your network is 192.168.32.0 than your subnet mask would be 255.255.255.0
0

Featured Post

What Is Threat Intelligence?

Threat intelligence is often discussed, but rarely understood. Starting with a precise definition, along with clear business goals, is essential.

Join & Write a Comment

To setup a SonicWALL for policy based routing to be used with the Websense Content Gateway there are several steps that need to be completed. Below is a rough guide for accomplishing this. One thing of note is this guide is intended to assist in the…
The DROP (Spamhaus Don't Route Or Peer List) is a small list of IP address ranges that have been stolen or hijacked from their rightful owners. The DROP list is not a DNS based list.  It is designed to be downloaded as a file, with primary intention…
It is a freely distributed piece of software for such tasks as photo retouching, image composition and image authoring. It works on many operating systems, in many languages.
When you create an app prototype with Adobe XD, you can insert system screens -- sharing or Control Center, for example -- with just a few clicks. This video shows you how. You can take the full course on Experts Exchange at http://bit.ly/XDcourse.

744 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

11 Experts available now in Live!

Get 1:1 Help Now