Linode Forum
Linode Community Forums
 FAQFAQ    SearchSearch    MembersMembers      Register Register 
 LoginLogin [ Anonymous ] 
Post new topic  Reply to topic
Author Message
 Post subject: Port blocks
PostPosted: Wed Sep 15, 2004 2:05 am 
Why are certain ports blocked (eg 79, 7000)?

If I choose to run a fingerd (port 79) or an IRC server on port 7000 why shouldn't I be free to use these ports?

One of the major attractions of an linode is the freedom. Various distributions to use, install whatever software you like.... This diminishes if you don't have a completely open pipe.


Top
   
 Post subject: Don't you get it?
PostPosted: Wed Sep 15, 2004 2:23 am 
The whole point is for your safety, not restriction. I appreciate the effort taken.


Top
   
 Post subject: Re: Don't you get it?
PostPosted: Wed Sep 15, 2004 2:45 am 
oldosadmin wrote:
The whole point is for your safety, not restriction. I appreciate the effort taken.


huh? Most of the listed port blocks related to Windows trojans. How does this protect your linode?


Top
   
 Post subject: Re: Don't you get it?
PostPosted: Wed Sep 15, 2004 3:06 am 
Offline
Linode Staff
User avatar

Joined: Tue Apr 15, 2003 6:24 pm
Posts: 3090
Website: http://www.linode.com/
Location: Galloway, NJ
guest1 wrote:
Most of the listed port blocks related to Windows trojans. How does this protect your linode?


Most of the ports blocked are UNIX related, not Windows:

Code:
79/tcp     filtered    finger                               
111/tcp    filtered    sunrpc                 
137/tcp    filtered    netbios-ns             
138/tcp    filtered    netbios-dgm             
139/tcp    filtered    netbios-ssn             
449/tcp    filtered    as-servermap           
513/tcp    filtered    login                   
514/tcp    filtered    shell                   
515/tcp    filtered    printer                 
555/tcp    filtered    dsf                     
2049/tcp   filtered    nfs                     
4045/tcp   filtered    lockd                   
6969/tcp   filtered    acmsoda                 
7000/tcp   filtered    afs3-fileserver         
7100/tcp   filtered    font-service           
12345/tcp  filtered    NetBus                 
12346/tcp  filtered    NetBus                 
27665/tcp  filtered    Trinoo_Master           
31337/tcp  filtered    Elite


These ports are blocked for good reasons. If you can give me a good enough reason to unblock them, I'll consider it. But, fingerd for IRC isn't going to cut it.

With all of the existing Linode customers, a good number have been with us for more than a year and a half, and no one has complained thus far makes me inclined to keep things how they are...

-Chris


Top
   
 Post subject: Re: Don't you get it?
PostPosted: Wed Sep 15, 2004 4:16 am 
Code:
79/tcp     filtered    finger                               
111/tcp    filtered    sunrpc                 
137/tcp    filtered    netbios-ns             
138/tcp    filtered    netbios-dgm             
139/tcp    filtered    netbios-ssn             
449/tcp    filtered    as-servermap           
513/tcp    filtered    login                   
514/tcp    filtered    shell                   
515/tcp    filtered    printer                 
555/tcp    filtered    dsf                     
2049/tcp   filtered    nfs                     
4045/tcp   filtered    lockd                   
6969/tcp   filtered    acmsoda                 
7000/tcp   filtered    afs3-fileserver         
7100/tcp   filtered    font-service           
12345/tcp  filtered    NetBus                 
12346/tcp  filtered    NetBus                 
27665/tcp  filtered    Trinoo_Master           
31337/tcp  filtered    Elite


These ports are blocked for good reasons. If you can give me a good enough reason to unblock them, I'll consider it. But, fingerd for IRC isn't going to cut it.

With all of the existing Linode customers, a good number have been with us for more than a year and a half, and no one has complained thus far makes me inclined to keep things how they are...

-Chris[/quote]

Basically I am looking for a UML provider that offers an open pipe as a policy. This way I am confident than in the future they will not block any ports that I am relying on. This has currently happened with by cable supplier.

I would like to define my own network access policy using iptables based on the services I will be offering. These may or may not be the ones you have blocked, but I think it should be left to the user to decide. Considering that you recommend running a service on a different port if the port is currently blocked, it doesn't really offer any additional security. The cases where these port blocks may provide extra security is when a user enables every server on a Linux distributions and neglects to keep it up to date with security patches.


Top
   
 Post subject:
PostPosted: Wed Sep 15, 2004 11:04 am 
Offline
Senior Member

Joined: Sun Mar 14, 2004 9:18 pm
Posts: 116
Website: http://michael.susens-schurter.com/
WLM: mschurter@yahoo.com
Yahoo Messenger: mschurter
Location: Peoria, IL
i wouldn't worry about ports you use being blocked. linode may not have "open pipe as a policy" but i've never had a problem with useful ports being blocked or heard of someone having a problem.

i'd look at it more as having a policy of forcing admins to adopt a minimal amount of security than a policy of blocking ports.


Top
   
 Post subject:
PostPosted: Wed Sep 15, 2004 12:57 pm 
Offline
Junior Member

Joined: Sat Sep 11, 2004 11:43 pm
Posts: 49
? port 7000 isnt blocked on my linode heh :o


Top
   
 Post subject:
PostPosted: Wed Sep 15, 2004 2:44 pm 
Offline
Linode Staff
User avatar

Joined: Tue Apr 15, 2003 6:24 pm
Posts: 3090
Website: http://www.linode.com/
Location: Galloway, NJ
Those ports are only blocked at the Dallas datacenter (host1-8, host27 and up).

-Chris


Top
   
 Post subject:
PostPosted: Tue Sep 21, 2004 1:32 am 
Are any ports blocked at the HE data centre?

I was hoping to get a linode at HE, as ping times are significantly better than The Planet from where I am located (Australia).


Top
   
 Post subject:
PostPosted: Tue Sep 21, 2004 2:34 am 
Offline
Senior Member
User avatar

Joined: Mon Jun 23, 2003 1:25 pm
Posts: 260
guest1 wrote:
Are any ports blocked at the HE data centre?


No


Top
   
Display posts from previous:  Sort by  
Post new topic  Reply to topic


Who is online

Users browsing this forum: No registered users and 1 guest


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum

Search for:
Jump to:  
RSS

Powered by phpBB® Forum Software © phpBB Group