K
Kristi
Hi, not sure where to post this.
Outbound settings are:
title [ Security Level Medium OUT rules ]
begin
# Protocol Match conditions
DropAddr
PassPacket
pass to port 80 >> done
pass from port 80 >> done
pass protocol udp, to port 53 >> done
pass to port 20 >> done
pass from port 20 >> done
pass to port 21 >> done
pass to port 110 >> done
pass to port 119 >> done
pass to port 143 >> done
pass to port 220 >> done
pass to port 25 >> done
pass to port 443 >> done
pass to port 500 >> done
pass protocol 50 >> done
pass icmp-type request >> done
# Failed to match
DropPacket
drop to port >= 135, to port <= 139 >> done, alert 4 [Dropping NETBIOS
Traffic]
drop all >> alert 1 [ Packet to be dropped unless Service enabled ]
end
It is blocking one access (entry from log):
Source IP: 192.168.1.47 Destination IP: 198.66.9.81
Protocol: TCP
Source Port: 1422 Destination Port: 30150
TCP Flags: 02 ( syn )
The log flags it as though it had matched the netbios argument.
and I'm darned if I know why.
thanks for any help or directions as to where I should post this.
(Westell 2200 modem using custom settings ("medium" with one line added to
allow echo out)
Kristi
Outbound settings are:
title [ Security Level Medium OUT rules ]
begin
# Protocol Match conditions
DropAddr
PassPacket
pass to port 80 >> done
pass from port 80 >> done
pass protocol udp, to port 53 >> done
pass to port 20 >> done
pass from port 20 >> done
pass to port 21 >> done
pass to port 110 >> done
pass to port 119 >> done
pass to port 143 >> done
pass to port 220 >> done
pass to port 25 >> done
pass to port 443 >> done
pass to port 500 >> done
pass protocol 50 >> done
pass icmp-type request >> done
# Failed to match
DropPacket
drop to port >= 135, to port <= 139 >> done, alert 4 [Dropping NETBIOS
Traffic]
drop all >> alert 1 [ Packet to be dropped unless Service enabled ]
end
It is blocking one access (entry from log):
Source IP: 192.168.1.47 Destination IP: 198.66.9.81
Protocol: TCP
Source Port: 1422 Destination Port: 30150
TCP Flags: 02 ( syn )
The log flags it as though it had matched the netbios argument.
and I'm darned if I know why.
thanks for any help or directions as to where I should post this.
(Westell 2200 modem using custom settings ("medium" with one line added to
allow echo out)
Kristi