Skip site navigation (1)Skip section navigation (2)
Date:      Wed, 15 Aug 2001 02:09:20 +0100
From:      "Mark Hughes" <mark@dvdnews.co.uk>
To:        "Richard Shea" <rshea@my-deja.com>, <freebsd-questions@FreeBSD.ORG>
Subject:   Re: firewalls + MSN Messenger
Message-ID:  <009301c12526$feff8c70$e4a5fea9@mark2>
References:  <200108150055.RAA14956@mail16.bigmailbox.com>

next in thread | previous in thread | raw e-mail | index | archive | help
> Hi - Does anyone know what tcp/udp ports products such as MSN Messenger
use ? AOL have something similar although I can't remember the name they
give it.
>
> I want to be sure I've got these blocked on my firewall.

You could have a problem there....as far as I know MSN will use ANY port it
can find, if you block off everything but say port 80 it'll go right ahead
and use that, or whatever. So I'm told...

However, you could block access to the MSN servers - rather than blocking
the ports if you just block all traffic to...

64.4.13.0/24

for MSN Messenger, this should work...well, that's what I use to ALLOW
access to it with IPFW (dynamic rules timeout causing all manner of
weirdness on the part of messenger, so I've added in a permanent hole to
that netblock. probably many screamingly good reasons why i shouldn't do
that however it's not a majorly important machine for anything).

YMMV, and I could be wrong, etc.

AIM is the AOL one, and I think that also uses something similar to find
ports it can use.

Of course, a third way of handling it is by having an AUP and enforcing it
with your users, and this way works irrespective of what ports are used :)

HTH,
Mark



To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-questions" in the body of the message




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?009301c12526$feff8c70$e4a5fea9>