Avatar of ragot
ragot
Flag for Singapore asked on

Netscreen-25 configuration for port blocking


 How to block ports in Netscreen-25 firewall?
Software Firewalls

Avatar of undefined
Last Comment
ragot

8/22/2022 - Mon
deimark

Which kind of port blocking are you looking for?  Is it physical port or logical port you are meaning?  Ie the physical interface or the application port?
ragot

ASKER
hi delmark, its the logical port. i want to block unncessary ports for forest trusting.
Qlemo

Are you using a "permit any-any-any" type of setup? That is, have you defined a policy allowing any traffic? By default all traffic crossing zones (Trust and Untrust) is rejected.
Experts Exchange has (a) saved my job multiple times, (b) saved me hours, days, and even weeks of work, and often (c) makes me look like a superhero! This place is MAGIC!
Walt Forbes
ragot

ASKER
hi qlemo, for now yes we are allowing any traffic
Qlemo

I still have no idea of your config. You can only block traffic crossing zones, because then policies are applied to the traffic. If you want to block traffic from one to another ethernet port in the same zone, you need to use the much more complicated policy-based routing.
Please describe what you want to do, and tell us more about your existing config. Is a VPN involved? Are you crossing zones?
deimark

Not true qlemo. You don't need to use PBR to apply a policy on intrazone traffic. Simply tick the box for "intrazone block" on the zone and then you will need to add specific policies ultimate allow the traffic.

@ ragot. Can you give us a but more info on what you are trying to do her?  Please give an example if the policlcies you have already and exactly what you are trying to achieve ie block http from x to y

We can certainly help you here but we need a but more info to advise correctly
⚡ FREE TRIAL OFFER
Try out a week of full access for free.
Find out why thousands trust the EE community with their toughest problems.
ragot

ASKER
hi qlemo, delmark

i have policies here that allow all, of course that is not secure. now i want to allow only ports use for forest trusting.

thanks for your replies.
ragot

ASKER
@qlemo: yes there is vpn involved. im connected to main office with all traffic allow
Qlemo

Do you use a route based or policy based VPN? Anyway, you will have a policy allowing the VPN traffic?! You can just modify that to allow only some ports: Create custom services containing NetBIOS (135, 137-139, each udp and tcp, and 445/tcp) or use the predefined ones.  Than include those as service in your VPN or Permit policy instead of "any".
Your help has saved me hundreds of hours of internet surfing.
fblack61
SOLUTION
deimark

THIS SOLUTION ONLY AVAILABLE TO MEMBERS.
View this solution by signing up for a free trial.
Members can start a 7-Day free trial and enjoy unlimited access to the platform.
See Pricing Options
Start Free Trial
GET A PERSONALIZED SOLUTION
Ask your own question & get feedback from real experts
Find out why thousands trust the EE community with their toughest problems.
ragot

ASKER

thanks for both of you on your answers.

 i saw a guide on how to create custom services, there are fields like :

 Source Port : Low and High
 Destination Port : Low and High
 ICMP : Low and High

 from this article : http://support.microsoft.com/kb/179442  there is client and server port. it is the source and destination port field right? but where will i put the port numbers? low or high?

thanks
ASKER CERTIFIED SOLUTION
Qlemo

THIS SOLUTION ONLY AVAILABLE TO MEMBERS.
View this solution by signing up for a free trial.
Members can start a 7-Day free trial and enjoy unlimited access to the platform.
See Pricing Options
Start Free Trial
⚡ FREE TRIAL OFFER
Try out a week of full access for free.
Find out why thousands trust the EE community with their toughest problems.
ragot

ASKER
thanks qlemo for your reply. im reading thru your last 2 posts and i sum it up as this :

create custom service or predefined services and add the services into policy instead of any..

so in this case the firewall will be limited to predefined ports and services which will be secure. am i correct?
SOLUTION
Qlemo

THIS SOLUTION ONLY AVAILABLE TO MEMBERS.
View this solution by signing up for a free trial.
Members can start a 7-Day free trial and enjoy unlimited access to the platform.
See Pricing Options
Start Free Trial
⚡ FREE TRIAL OFFER
Try out a week of full access for free.
Find out why thousands trust the EE community with their toughest problems.
ragot

ASKER
what if the default policy has been changed to allow all? does it need to be deleted and create a new policy?
⚡ FREE TRIAL OFFER
Try out a week of full access for free.
Find out why thousands trust the EE community with their toughest problems.
SOLUTION
Qlemo

THIS SOLUTION ONLY AVAILABLE TO MEMBERS.
View this solution by signing up for a free trial.
Members can start a 7-Day free trial and enjoy unlimited access to the platform.
See Pricing Options
Start Free Trial
⚡ FREE TRIAL OFFER
Try out a week of full access for free.
Find out why thousands trust the EE community with their toughest problems.
ragot

ASKER

 will there be no conflicts on that? thanks a lot qlemo :)
Qlemo

No, no conflicts. Policies are applied top-down, so you should define the most specific on top, the most generic on bottom.
ragot

ASKER
thanks a lot ! you are very helpful !
thanks to delmark also..
I started with Experts Exchange in 2004 and it's been a mainstay of my professional computing life since. It helped me launch a career as a programmer / Oracle data analyst
William Peck
ragot

ASKER
awesome!