Forum Home
Press F1
 
Thread ID: 54825 2005-02-23 09:02:00 Firewall setup Mike_H (2538) Press F1
Post ID Timestamp Content User
327586 2005-02-23 09:02:00 I have a router / firewall for my ADSL connection, but I don't have much information on how to set up the firewall.
Which ports should I leave open, which should I close?

I think I need to open
TCP port 80 for web
TCP port 25 for mail

I think I need to close
TCP port 23 to stop telnet
UDP port 161 to stop SNMP (it says so in the router user guide)

Apart from general advice, can anyone point me (URL) to a Beginners' Guide on this topic?


Thanks

Mike
Mike_H (2538)
327587 2005-02-23 09:42:00 The following ports are on stealth or closed on my computer which is a Mac by the way and they are all controlled by the built- in firewall on Mac OS X automatically without any configuration . It only needs to be turned on .

So for normal web and email use you do not need to have any of the listed ports open .

You can check your system at this link
. com/x/ne . dll?bh0bkyd2" target="_blank">grc . com


Checking the Most Common and
Troublesome Internet Ports
0

<nil>

Closed
Your computer has responded that this port exists but is currently closed to connections .



21

FTP

Stealth
There is NO EVIDENCE WHATSOEVER that a port (or even any computer) exists at this IP address!



22

SSH

Stealth
There is NO EVIDENCE WHATSOEVER that a port (or even any computer) exists at this IP address!



23

Telnet

Stealth
There is NO EVIDENCE WHATSOEVER that a port (or even any computer) exists at this IP address!



25

SMTP

Stealth
There is NO EVIDENCE WHATSOEVER that a port (or even any computer) exists at this IP address!



79

Finger

Stealth
There is NO EVIDENCE WHATSOEVER that a port (or even any computer) exists at this IP address!



80

HTTP

Stealth
There is NO EVIDENCE WHATSOEVER that a port (or even any computer) exists at this IP address!



110

POP3

Stealth
There is NO EVIDENCE WHATSOEVER that a port (or even any computer) exists at this IP address!



113

IDENT

Stealth
There is NO EVIDENCE WHATSOEVER that a port (or even any computer) exists at this IP address!



119

NNTP

Stealth
There is NO EVIDENCE WHATSOEVER that a port (or even any computer) exists at this IP address!



135

RPC

Stealth
There is NO EVIDENCE WHATSOEVER that a port (or even any computer) exists at this IP address!



139

Net
BIOS

Stealth
There is NO EVIDENCE WHATSOEVER that a port (or even any computer) exists at this IP address!



143

IMAP

Stealth
There is NO EVIDENCE WHATSOEVER that a port (or even any computer) exists at this IP address!



389

LDAP

Stealth
There is NO EVIDENCE WHATSOEVER that a port (or even any computer) exists at this IP address!



443

HTTPS

Stealth
There is NO EVIDENCE WHATSOEVER that a port (or even any computer) exists at this IP address!



445

MSFT
DS

Stealth
There is NO EVIDENCE WHATSOEVER that a port (or even any computer) exists at this IP address!



1002

ms-ils

Stealth
There is NO EVIDENCE WHATSOEVER that a port (or even any computer) exists at this IP address!



1024

DCOM

Stealth
There is NO EVIDENCE WHATSOEVER that a port (or even any computer) exists at this IP address!



1025

Host

Stealth
There is NO EVIDENCE WHATSOEVER that a port (or even any computer) exists at this IP address!



1026

Host

Stealth
There is NO EVIDENCE WHATSOEVER that a port (or even any computer) exists at this IP address!



1027

Host

Stealth
There is NO EVIDENCE WHATSOEVER that a port (or even any computer) exists at this IP address!



1028

Host

Stealth
There is NO EVIDENCE WHATSOEVER that a port (or even any computer) exists at this IP address!



1029

Host

Stealth
There is NO EVIDENCE WHATSOEVER that a port (or even any computer) exists at this IP address!



1030

Host

Stealth
There is NO EVIDENCE WHATSOEVER that a port (or even any computer) exists at this IP address!



1720

H . 323

Stealth
There is NO EVIDENCE WHATSOEVER that a port (or even any computer) exists at this IP address!



5000

UPnP

Stealth
There is NO EVIDENCE WHATSOEVER that a port (or even any computer) exists at this IP address!
Safari (3993)
327588 2005-03-07 06:36:00 Thanks, Safari

Between the firewall user guide and your pointer to grc.com, I have managed to seal up the firewall fairly completely.
Actually, a bit too completely, my kids say they can't use the audio-chat feature in MSN Messenger any more!

Any ideas which port(s) I'd need to open to get that to work?
Mike_H (2538)
1