Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations strongm on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

How to block port 445 on the PIX 515? 1

Status
Not open for further replies.

TGaylor

MIS
Jul 27, 2004
39
US
The PIX 515 is a state-based firewall appliance, therefore in-coming traffic over port 445 would be blocked by default unless a “conduit” was created to open it; correct?
I need to make certain traffic over port 445 is blocked.

Thanks in advance for the help,


Tom
 
Yes. I'd suggest blocking it outbound as well, to help ensure that you don't inadvertantly become part of the problem.
 
May I ask how one would block outbound traffic on port 445?

Thanks,


Tom
 
With an inbound access-list on the inside interface. Something like:

access-list inside_acl deny tcp any any eq 445
access-list inside_acl permit ip any any
access-group inside_acl in interface inside

Recent versions of FOS allow both access lists and conduits; ACLs are recommended and override conduits if both are present. Also, there's a Pix-specific forum here where there would be a lot of help.


 
Access-list it is; thanks very much for your help!

Tom
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top