CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have sign-ups from twelve different countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 7/14, 8/25, 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Miscellaneous
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-11-15
evo22 evo22 is offline
Member
 
Join Date: 2007-05-10
Posts: 37
Rep Power: 0
evo22 has an average reputation (10+)
Default Open Ports.......

We have approxamatly 300 IP40/45/60 at different retail locations of ours. We would like to build a new rulebase for these firewalls.

When I filter all traffic in Tracker comming from the stores....there are alot of ports open. How would you suggest I'd begin to start identifing an locking down these ports?

Here is just a sample of some of the open ports:

59929
10838
19523
49211
5588
7811
52492
31787
13964
7988
3470
14228
58151
7574
1886
8294
40364
3524
40364
26108
11393
13748
3563
37649
7661
16439
20414
57110
3509
57110
53600
46655
55388
18974
3479
10346
32789
19640
8033
63911
50618
60170
36581


There are many more.

I know we need to know which ones we use often. Like 21, 22, 443, 80 etc.
but I don't want to block ports that I haven't identified as port we use.

any input or direction would be appricated!

thanks
Reply With Quote
  #2 (permalink)  
Old 2007-11-15
RayPesek RayPesek is offline
Senior Member
 
Join Date: 2006-03-19
Location: Northern Ohio
Posts: 861
Rep Power: 3
RayPesek has an average reputation (10+)
Default Re: Open Ports.......

Are you looking in the Source Port column or the Service column? Those are normal for the Source Port.

The computer initiating the connection generally picks a random source port up high to initiate the connection to the destinations Service port.

Ray
Reply With Quote
  #3 (permalink)  
Old 2007-11-16
evo22 evo22 is offline
Member
 
Join Date: 2007-05-10
Posts: 37
Rep Power: 0
evo22 has an average reputation (10+)
Default Re: Open Ports.......

Thank you for your quick reply; I was looking at the source port.

In regards to the service column, how would you suggest I start this process of eliminating questionable ports?
Reply With Quote
  #4 (permalink)  
Old 2007-11-17
RayPesek RayPesek is offline
Senior Member
 
Join Date: 2006-03-19
Location: Northern Ohio
Posts: 861
Rep Power: 3
RayPesek has an average reputation (10+)
Default Re: Open Ports.......

If your log files cover a fair amount of time, a couple of months or so, you could export them to a text file from the File menu and import it into Excel. Use " as the delimiter.

Then sort on Destination and you'll see what hosts are getting traffic on what ports.

Sort on Source and you'll see what hosts are trying to use which services.

Then sort on Services and you'll see all that are in use by which source and destination.

Assuming you know what the allowed destinations are, it should be pretty easy to get it all sorted out, so to speak. :-)

Take care,

Ray
Reply With Quote
  #5 (permalink)  
Old 2007-11-27
evo22 evo22 is offline
Member
 
Join Date: 2007-05-10
Posts: 37
Rep Power: 0
evo22 has an average reputation (10+)
Default Re: Open Ports.......

I have port 1301 connecting to our exchange server and when I block it. Our remote users can't connect. What is this port used for? I've tried to search for information.

thank you in advance!
Reply With Quote
  #6 (permalink)  
Old 2007-12-26
vijayant vijayant is offline
Senior Member
 
Join Date: 2006-05-24
Location: India
Posts: 109
Rep Power: 3
vijayant has an average reputation (10+)
Default Re: Open Ports.......

iad2 1031/tcp BBN IAD
iad2 1031/udp BBN IAD


This is the BBN (Bolt, Beranek and Newman) Interface Access Device,
which operates as a bridge/router between IP, X.25, asynch links, etc.

Re: What is BBN IAD?
Reply With Quote
  #7 (permalink)  
Old 2008-01-02
melipla melipla is offline
Senior Member
 
Join Date: 2006-01-25
Posts: 724
Rep Power: 3
melipla has an average reputation (10+)
Default Re: Open Ports.......

Quote:
Originally Posted by evo22 View Post
I have port 1301 connecting to our exchange server and when I block it. Our remote users can't connect. What is this port used for? I've tried to search for information.
Since its an Exchange server, its most likely a RPC connection. Microsoft is notoriously hard to lock down via port restrictions, there are a lot of server side & client side changes you need to make in order to do it right.

By RPC connection I'm referring to the client accessing the server via DCOM (135/tcp), in that DCOM connection the server will respond a new port (>1024/tcp aka tcp-high-ports) which the client will use for the rest of the session. So you will then see the client access the server on whichever port the server specified (in this case 1301).

If you have no server side / client side modifications in place then you will most likely see each client using a different port. In some cases it can be sequential, depends on how long the port is used for and how many clients you have.

As for working your way through the list of ports, I would recommend with starting with ports that are < 1024, as these are more than likely to be tied to a valid service. While there are services in port ranges higher then 1024 (such as SQL ports) they are more likely to be back connection ports and in some cases can be safely dropped.
__________________
Its all in the documentation.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 13:24.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0