Blocking Ports
130
Firebox X Edge e-Series
X Font Server (port 7100)
Many versions of X-Windows operate X Font Servers. The X Font Servers operate as the super-
user on some hosts.
NFS (port 2049)
NFS (Network File System) is a frequently used TCP/IP service where many users use the same
files on a network. But, the new versions have important authentication and security problems.
To supply NFS on the Internet can be very dangerous.
T
he portmapper frequently uses the port
2049 for NFS. If you use NFS, make sure that NFS uses the port 2049 on all your systems.
rlogin, rsh, rrcp (ports 513, 514)
These services give remote access to other computers. They are a security risk and many
attackers probe for these services.
RPC portmapper (port 111)
The RPC Services use port 111 to find which ports a given RPC server uses. The RPC services are
easy to attack through the Internet.
port 8000
Many vendors use this port, and there are many security problems related to it.
port 1
The TCPmux service uses Port 1, but not frequently. You can block it to make it more difficult for
the tools that examine ports.
port 0
This port is always blocked by the Firebox. You cannot add this port to the Blocked Ports list. You
cannot allow traffic on port 0 through the Firebox.
Avoiding problems with blocked ports
Be very careful if you block port numbers higher than 1023. Clients frequently use these source port
numbers.
Adding a port to the blocked ports list
1
To connect to the System Status page, type
https://
in the browser address bar, and the IP
address of the Firebox X Edge trusted interface.
The default URL is https://192.168.111.1
2
From the navigation bar, click
Firewall
>
Intrusion Prevention
. Click on the
Blocked Ports
tab.
Содержание Firebox X20E
Страница 20: ...The Firebox X Edge and Your Network 8 Firebox X Edge e Series...
Страница 32: ...Using the Quick Setup Wizard 20 Firebox X Edge e Series...
Страница 64: ...Viewing the Configuration File 52 Firebox X Edge e Series...
Страница 92: ...Configuring BIDS 80 Firebox X Edge e Series...
Страница 102: ...Configuring the Wireless Card on Your Computer 90 Firebox X Edge e Series...
Страница 114: ...Configuring Policies for the Optional Network 102 Firebox X Edge e Series...
Страница 138: ...Using Additional Services for Proxies 126 Firebox X Edge e Series...
Страница 158: ...Working with Firewall NAT 146 Firebox X Edge e Series...
Страница 166: ...Using Certificates on the Firebox X Edge 154 Firebox X Edge e Series...
Страница 208: ...Updating Gateway AV IPS 196 Firebox X Edge e Series...
Страница 220: ...Frequently Asked Questions 208 Firebox X Edge e Series...
Страница 302: ...Limited Hardware Warranty 290 Firebox X Edge e Series...
Страница 310: ...298 Firebox X Edge e Series...