Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations derfloh on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

What UDP traffic should I allow

Status
Not open for further replies.

ianbla

IS-IT--Management
Oct 31, 2001
156
GB
I am just looking at my SYSLOG Deamon and there are a lot of entries for UDP traffic

what UDP ports should I be allowing?
 
It depeneds what you are doing. Are you talking about incoming or outgoing traffic?
 
HI.

Post here some of those lines to get more info.

Regular UDP traffic is DNS which is normaly on port 53 but not always (some linux based mail servers use random ports for DNS - I don't know why and how exactly).

UDP port 1434 is related to the latest SQL worm and should normaly be blocked.

UDP port 137 is for Netbios and should be blocked - but you will get probes on that ports regulary.

A common pix configuration will block all inbound UDP traffic, and will permit outbound UDP traffic to port 53 unless any outbound traffic is permitted (the default implicit outbound rule).

Bye
Yizhar Hurwitz
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top