Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations Mike Lewis on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Services "Any" ?

Status
Not open for further replies.

techpearl

IS-IT--Management
Dec 3, 2002
25
0
0
SG
hi,

if the destination =any, services =any. Is that mean that every services/ports is allow to be access to everywhere?

What if the source going out by port 80 and the request coming back by port 81?

 
If the rule was S=any and D=any and Sv=any, then it would mean that anyone could go anywhere using any port, with the exception of X-11, which needs to be put in it's own rule, as a security measure.

So if the service was going out port 80 and coming back in port 81, then is should be fine. However, the above rule is not the most secure. We will create a custom service for instances like that. We use the tracker/log file to find out what is being dropped or not.
 
ASFAIK, Services will only be included as "any" if they're marked to be included as "any".

So choosing "any" as a Service won't necessarily include all TCP/UDP ports as one might expect.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top