Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations biv343 on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

conduit permit command

Status
Not open for further replies.

jkaufman

Technical User
Mar 15, 2004
2
US
Is there a difference between "conduit permit tcp host x.x.x.x any eq www" and conduit permit tcp host x.x.x.x eq I've had instances where one works and the other doesn't and one case recently where term svcs (port 3389) needed both before access was granted from outside.
 
conduit permit tcp host x.x.x.x any eq www"
You are saying anyone can come on port 80 only to host x.x.x.x who's listening on any port

conduit permit tcp host x.x.x.x eq You are saying anyone can come on any port to host x.x.x.x who's listening on port 80 only.
 
That was my understanding too...but then shouldn't either conduit work in almost all instances?
 
Nope because clients use dynamic ports above 1024 while servers usually listen on fixed ports below 1024. For your internal servers you should use the later one.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top