Endpoint Protection

 View Only
  • 1.  FireWall Rules

    Posted Mar 20, 2009 10:16 AM

    What other ports or rules do you guys add other than the basic out of box rules?



  • 2.  RE: FireWall Rules

    Posted Mar 20, 2009 02:53 PM

    There is no defined or set standard, in my opinion, with regards to ports and rules in a firewall, as the needs of everyone varies.

    However, depending on the needs of the business, than the individual, a plan is a good place to start.  For example, does your business allow users to chat on MSN, AIM, Yahoo Messenger, etc. 

    If you have a defined exclusions in the policies of the company for these and they are already centrally blocked by a firewall, than there is no need to duplicate the rules. 

    If you do not have a defined ruleset in a central firewall/router and are afraid of security breaches internally and externally, than you can block everything and open slowly what you need.  That being said, if you want your users to have internet access, Ports: 80, 443, DNS port 53, WINS (if applicable) port: 42 for replication to other server, 137 - 138 and 139 are basically a must. 

    NTP for clocks, port 123 and so on... 



  • 3.  RE: FireWall Rules
    Best Answer

    Posted May 22, 2009 12:10 PM
    You should know which services and applications you are running in your network. Then you can look into the SEPM firewall rulebase to see if a service has not been defined for traffic approval. Also, you can monitor the applications in your network with the help of SEPM and create appropriate rules for that.

    Cheers,
    Aniket