[Search for users] [Overall Top Noters] [List of all Conferences] [Download this site]

Conference noted::seal

Title:SEAL
Moderator:GALVIA::SMITH
Created:Mon Mar 21 1994
Last Modified:Fri Jun 06 1997
Last Successful Update:Fri Jun 06 1997
Number of topics:1989
Total number of notes:8209

1757.0. "What does the Firewall do if you ftp/telnet to any port?" by TENNIS::KAM (AltaVista Software 714/261-4133 DTN 535.4133) Sat Feb 01 1997 04:01

    What happens in the AltaVista Firewall when a user telnet's, ftp's to
    random ports on the Firewall?  I know that the Firewall will fail to
    pass the connection but will it log that event?  No process is
    listening on ALL ports?  Or does a process, periodically, scan all the
    ports?
    
    The customer indicated that if you ftp or telnet, can't remember which
    one, to Port 135, switch to ANSI mode, type any character, then
    disconnect the system utilization goes to 100 percent.  I guess it's
    trying to process the activity on Port 135?  The system doesn't crash
    but response time for the user's activity through the Firewall suffers
    considerably.
    
    This is Windows NT scenario.
    
       
    	Regards,
    
T.RTitleUserPersonal
Name
DateLines
1757.1QUICHE::PITTAlph a ha is better than no VAX!Wed Feb 05 1997 08:3411
    On UNIX, there are three possible outcomes:  there may be a service on
    that port, in which case the connection will be logged and treated
    according to the rules for that service;  there may be a strafe service
    on the port, in which case the firewall remembers (but doesn't log, I
    think) the connection;  or there may be no response at all - i.e.
    no-one listening, or defined to receive connections, on the port - in
    which case there is no log ...
    
    On Windows NT, who knows?  Bill Gates?
    
    T
1757.2BIGUN::nessus.cao.dec.com::MayneWake up, time to dieThu Feb 06 1997 22:5913
On the firewall I just installed, the customer preferred the "keep 'em guessing" 
approach. The telnet proxy is disabled, but the "you cannot use this" message 
has been replaced by

	<html>
	<body>
	The Web server is down.
	</body>
	</html>

Try to telnet, get a Web server. 8-)

PJDM