1 |
TCP |
tcpmux |
TCP port multiplexer. Rarely used. |
Block |
|
7 |
UDP, TCP |
echo |
Echos UDP packets and characters sent down
TCP streams.
|
Block[2] |
|
9 |
UDP, TCP |
discard |
Accepts connections, but discards the data.
|
Block |
|
11 |
TCP |
systat |
System status - reports the active users
on your system. Some systems connect this to who.
|
Block |
|
13 |
UDP, TCP |
daytime |
Time of day in human-readable form. |
Block[3] |
|
15 |
TCP |
netstat |
Network status, human-readable. Obsolete (officially
unassigned as of 10/94).
|
Block |
|
17 |
UDP |
qotd |
Quote of the day. |
Block |
|
19 |
UDP, TCP |
chargen |
Character generator. |
Block |
|
20 |
TCP |
ftp-data |
Data and command ports for FTP.
Sniff
.
|
requires special handling. |
|
21 |
TCP |
ftp |
|
|
|
23 |
TCP |
telnet |
Telnet virtual terminal.
Sniff.
|
Be careful.
[4] |
|
24 |
UDP, TCP |
|
For use by private email systems. |
Block |
|
25 |
TCP |
smtp |
Email. |
Allow to your firewall gate or bastion host.
|
|
37 |
UDP, TCP |
time |
Time of day, in machine-readable form. |
Block |
|
38 |
UDP, TCP |
rap |
Route Access Protocol. |
Block |
|
42 |
UDP, TCP |
name |
Host Name Server.
Obsolete.
|
Block |
|
43 |
TCP |
whois |
Normally only run by NICs. |
Outbound only or Block. |
|
48 |
UDP, TCP |
auditd |
Digital Equipment Corporation audit daemon.
|
Block |
|
49 |
UDP |
tacacs |
Sniff. Spoof.
|
Block. You should place your tacacs authentication
servers on the same side of your firewall as your terminal concentrators.
|
|
53 |
UDP, TCP |
domain |
Domain Name Service.
Spoof.
|
Run separate nameservers for internal and external
use. If you use firewall proxies, then you only need to provide
DNS service on your firewall computer.
|
|
67, 68 |
UDP |
bootp |
Boot protocol. |
Block |
|
69 |
UDP |
tftp |
Trivial FTP. |
Block |
|
70 |
TCP |
gopher, gopher+
|
Text-based information service.
Sniff.
|
Outbound access with proxies. Inbound connections
only to an organizational gopher server running on a special host.
|
|
79 |
TCP |
finger |
Return information about a particular user
account or machine.
|
Outbound only.
[5]
(You
may wish to refer inbound finger queries to a particular message.)
|
|
80 |
TCP |
http |
World Wide Web.
Sniff. Spoof.
|
Outbound access with proxies. Inbound connections
only to an organizational WWW server running on a special host.
|
|
87 |
TCP |
link |
|
Block |
|
88 |
UDP |
kerberos |
Distributed authentication mechanism. |
Block unless you need inter-realm authentication.
|
|
94 |
UDP, TCP |
objcall |
Tivoli Object Dispatcher. |
Block |
|
95 |
TCP |
supdup |
Virtual terminal similar to Telnet, rarely
used. S
niff.
|
Block |
|
109 |
TCP |
pop-2 |
Post Office Protocol, allows reading mail over
Internet.
Sniff.
|
Block unless there is a specific
need to access email through firewall. Consider using APOP, which
is not susceptible to password sniffing. If you do pass this service,
pass inbound connections only to your email host.
|
|
110 |
TCP |
pop-3 |
Better Post Office Protocol. S
niff.
|
|
|
111 |
UDP, TCP |
sunrpc |
Sun RPC portmapper.
Spoof.
[6] |
Block |
|
113 |
TCP |
auth |
TCP authentication service. Identifies the
username belonging to a TCP connection.
Spoof.
|
Limit or block incoming requests.[7] |
|
119 |
TCP |
nntp |
Network News Transport Protocol. |
Block with exceptions.[8] |
|
121 |
UDP, TCP |
erpc |
Encore Expedited Remote Procedure Call.
|
Block |
|
123 |
UDP, TCP |
ntp |
Network Time Protocol.
Spoof.
|
Block with exceptions.[9] |
|
126 |
UDP, TCP |
unitary |
Unisys Unitary Login. |
Block |
|
127 |
UDP, TCP |
locus-con |
Locus PC-Interface Conn Server. |
Block |
|
130 |
UDP, TCP |
cisco-fna |
Cisco FNATIV. |
Block with exceptions. |
|
131 |
UDP, TCP |
cisco-tna |
Cisco TNATIVE. |
Block with exceptions. |
|
132 |
UDP, TCP |
cisco-sys |
Cisco SYSMAINT. |
Block with exceptions. |
|
137 |
UDP, TCP |
netbios-ns |
NETBIOS Name Service. |
Block NETBIOS unless there is
a specific host with which you need to exchange NETBIOS information.
NETBIOS over TCP/IP is best handled with encrypted tunneling.
|
|
138 |
UDP, TCP |
netbios-dgm |
NETBIOS Datagram Service. |
|
|
139 |
UDP, TCP |
netbios-ssn |
NETBIOS Session Service. |
|
|
144 |
UDP, TCP |
news |
Sun NeWS (Network Window System). Possibly
Sniff. Spoof. Obsolete.
|
Block |
|
156 |
UDP, TCP |
sqlsrv |
SQL Service.
Sniff.
|
Block |
|
161 |
UDP, TCP |
snmp |
Simple Network Management Protocol agents.
Spoof. Sniff.
|
Block |
|
162 |
UDP, TCP |
snmptrap |
SNMP traps. |
Block under most circumstances, although you
may wish to allow traps from an external gateway to reach your internal
network monitors.
|
|
177 |
UDP, TCP |
xdmcp |
X Display Manager (XDM) Control Protocol.
Sniff.
Possibly Spoof.
|
Block. You may wish to allow outgoing connections
in special circumstances.
|
|
178 |
UDP, TCP |
NSWS |
NEXTSTEP Window Server. Possibly Sniff.
Spoof.
|
Block |
|
194 |
UDP, TCP |
irc |
Internet Relay Chat Protocol. |
Block |
|
199 |
UDP, TCP |
smux |
SMUX (IBM). |
Block |
|
200 |
UDP, TCP |
src |
IBM System Resource Controller. |
Block |
|
201 |
UDP, TCP |
at-rtmp |
AppleTalk Routing Maintenance. |
Block AppleTalk unless there
is a specific host or network with which you need to exchange AppleTalk
information. AppleTalk over TCP/IP is best handled through
encrypted tunneling.
|
|
202 |
UDP, TCP |
at-nbp |
AppleTalk Name Binding. |
|
|
203 |
UDP, TCP |
at-3 |
AppleTalk Unused. |
|
|
204 |
UDP, TCP |
at-echo |
AppleTalk Echo. |
|
|
205 |
UDP, TCP |
at-5 |
AppleTalk Unused. |
|
|
206 |
UDP, TCP |
at-zis |
AppleTalk Zone Information. |
|
|
207 |
UDP, TCP |
at-7 |
AppleTalk Unused. |
|
|
208 |
UDP, TCP |
at-8 |
AppleTalk Unused. |
|
|
210 |
TCP |
wais |
WAIS server. Sniff. |
Block unless you run a server. |
|
220 |
TCP |
imap |
POP replacement. Sniff. |
Block unless there is a specific need to access
email through the firewall. If you do pass this service, pass inbound
connections only to your email host.
|
|
387 |
TCP |
avrp |
AppleTalk Routing. |
Block |
|
396 |
UDP, TCP |
netware-ip |
Novell Netware over IP. Sniff. |
Block |
|
411 |
UDP, TCP |
rmt |
Remote Tape. |
Block |
|
512 |
UDP |
biff |
Real-time mail notification. |
Block |
|
512 |
TCP |
exec |
Remote command execution. Sniff.Spoof.
|
Block |
|
513 |
UDP |
rwho |
Remote who command. |
Block |
|
513 |
TCP |
login |
Remote login.
Sniff. Spoof.
|
These protocols are vulnerable
to problems with "trusted hosts" and
.rhost
files.
Block them if at all possible.
|
|
514 |
TCP |
shell |
rsh
.
Sniff. Spoof.
|
|
|
514 |
UDP |
syslog |
syslog logging. |
Block |
|
515 |
TCP |
printer |
Berkeley lpr system.
Spoof.
|
Block |
|
517 |
UDP |
talk |
Initiate talk requests. |
You should probably block these
protocols for incoming and outgoing use. If you wish to permit your
users to receive talk requests from outside sites, then you must
allow user machines to receive TCP connections on any TCP/IP
port over 1024. The protocols further require that both hostnames
and usernames of your internal users be made available to outsiders.
talk can further be used to harass users.
|
|
518 |
UDP |
ntalk |
Initiate talk
requests. |
|
|
520 |
UDP |
route |
Routing control. Spoof. |
Block |
|
523 |
UDP, TCP |
timed |
Time server daemon. Spoof. |
Block |
|
532 |
UDP, TCP |
netnews |
Remote readnews. |
Block |
|
533 |
UDP, TCP |
netwall |
Network Write to all users. |
Block |
|
540 |
TCP |
uucp |
Used mostly for sending batches of Usenet news.
Sniff. Spoof.
|
Block unless there are specific hosts with
which you wish to exchange UUCP information.
|
|
550 |
UDP, TCP |
nrwho |
New rwho. |
Block |
|
566 |
UDP, TCP |
remotefs |
RFS remote filesystem. Sniff. Spoof. |
Block |
|
666 |
TCP |
mdqs |
Replacement for Berkeley's printer
system.
|
Block |
|
666 |
UDP, TCP |
doom |
Doom game. |
Block |
|
744 |
TCP |
FLEXlm |
FLEX license manager. |
Block |
|
754 |
TCP |
tell |
Used by send |
Block |
|
755 |
UDP |
securid |
Security Dynamics ACE/Server.
Sniff
[10]
|
Block |
|
765 |
TCP |
webster |
Dictionary service. |
Block |
|
1025 |
TCP |
listener |
System V Release 3 listener. |
Block |
|
1352 |
UDP, TCP |
lotusnotes |
Lotus Notes mail system. |
Block |
|
1525 |
UDP |
archie |
Tells you where things are on the Internet.
|
Block, except the specific archie servers you
want to use.
|
|
2000 |
TCP |
OpenWindows |
Sun proprietary window system. |
Block |
|
2049 |
UDP, TCP |
nfs |
Sun NFS Server (usually). Spoof. |
Block |
|
2766 |
TCP |
listen |
System V listener. |
Block |
|
3264 |
UDP, TCP |
ccmail |
Lotus cc:Mail. |
Block |
|
5130 |
UDP |
sgi-dogfight |
Silicon Graphics flight simulator. |
Block |
|
5133 |
UDP |
sgi-bznet |
Silicon Graphics tank demo. |
Block |
|
5500 |
UDP |
securid |
Security Dynamics ACE/Server version
2.
Sniff.
[11]
|
Block |
|
5510 |
TCP |
securidprop |
Security Dynamics ACE/Server slave.
Sniff.
[12]
|
Block |
|
5701 |
TCP |
xtrek |
X11 xtrek. |
Block |
|
6000 thru 6063
|
TCP |
x-server |
X11 server.
Sniff.
Spoof. |
Block |
|
6667 |
TCP |
irc |
Internet Relay Chat. |
Block |
|
7000 thru 7009
|
UDP, TCP |
afs |
Andrew File System. Spoof. |
Block |
|
7100 |
TCP |
font-service |
X Server font service. |
Block |
|