Networker

[Networker] TuneUp of packet filtering rules

2007-07-09 05:15:13
Subject: [Networker] TuneUp of packet filtering rules
From: Manel Rodero <manel AT FIB.UPC DOT EDU>
To: NETWORKER AT LISTSERV.TEMPLE DOT EDU
Date: Mon, 9 Jul 2007 11:13:12 +0200
Hello,

I'm tuning a packet filter firewall in our Legato Server (7.1.4 under Windows). I'm trying to define rules for the default Legato ports.

These input rules in the Legato Server seems to work very well:

        ALLOW
        Source Legato Clients / Ports 10001-30000
        Target Legato Server / Ports 7937-9936

        ALLOW
        Source Legato clients / Ports 7937,7938
        Target Legato Server / Ports Any / Flags NOT SYN

But, sometimes I catch errors in the firewall (it seems that doesn't affect the backup) for connections like these:

        Source Legato Client / Port 21830
        Target Legato Server / Port 843 / Flag SYN

So, there is an attempt of connection of this client to a port that doesn't have anything related to Legato, doesn't it?

So the questions are:

- Is the connection procedure for an scheduled backup always the same? (i.e. in the same order, using the same range ports, etc.)

Thank you very much.






--

o o o  Manel Rodero                   | LCFIB - UPC
o o o  Systems Manager                | Campus Nord - Modul B6
o o o  Laboratori de Calcul           | Jordi Girona, 1-3
U P C  Facultat Informatica Barcelona | 08034 Barcelona (Spain)
                                      |
       manel AT fib.upc DOT edu              | Tel: +00 34 93 401 6940
       http://www.fib.upc.edu/~manel  | Fax: +00 34 93 401 7040

To sign off this list, send email to listserv AT listserv.temple DOT edu and type 
"signoff networker" in the body of the email. Please write to networker-request 
AT listserv.temple DOT edu if you have any problems with this list. You can access the 
archives at http://listserv.temple.edu/archives/networker.html or
via RSS at http://listserv.temple.edu/cgi-bin/wa?RSS&L=NETWORKER

<Prev in Thread] Current Thread [Next in Thread>