Firewall Wizards mailing list archives

RE: MSN... stay away? or OK?


From: Joe Matusiewicz <joem () nist gov>
Date: Thu, 19 Oct 2000 09:41:34 -0400

At 01:02 PM 10/18/00, Michael.Owen () net-tel co uk wrote:
> Guru advice please.

I'm no guru, but I'll still comment!

> Could we allow clients to safely use MSN services including Netmeeting
> options with MSN from our LAN to the internet.

Ig. You need a firewall which can safely proxy H.323. Firewall-1, for example, has a proxy for it. Alternatively, you can follow Microsoft's advice for "configuring" your firewall, but I wouldn't recommend it. Basically, you have to allow UDP through to all ports above 1024. This is generally frowned upon. ;-)



Actually, it's just a teensy weensy more involved than that. From Microsoft's recommendation at: http://www.microsoft.com/Windows/Netmeeting/Corp/ResKit/Chapter4/default.asp

"To establish outbound NetMeeting connections through a firewall, the firewall must be configured to do the following: · Pass through primary TCP connections on ports 389, 522, 1503, 1720, and 1731. · Pass through secondary TCP and UDP connections on dynamically assigned ports (1024-65535)."

And that's all you have to do.  ;-)


-- Joe


_______________________________________________
firewall-wizards mailing list
firewall-wizards () nfr com
http://www.nfr.com/mailman/listinfo/firewall-wizards


Current thread: