08-13-2003 03:56 AM - edited 02-20-2020 10:55 PM
Am I right to assume that the handful of ports 69, 135, 139, 445 and 4444 are blocked by nature on the PIX? I have not expressly opened any of them as far as I can tell? I have looked around on the net and not found anyone talking about the PIX in conjunction with this worm. Thanks for you help.
08-13-2003 06:18 AM
Traffic from outside to inside is denied unless permitted. If you are not allowing the traffic for above mentioned ports using access-list or conduit, you are fine.
08-13-2003 08:23 AM
Thanks. It seemed that way, but I was worried that I had mis-understood my PIX documentation.
08-13-2003 03:03 PM
yea, it is blocked by default. but we should also search for the specific exe file. if the worm is already sitting at one of the inside hosts, then there would be a bit worry.
08-13-2003 04:14 PM
These ports are blocked from outside to inside (inbound traffic) interfaces only. They are not blocked from inside to outside (outbound traffic). If you have an infected PC on your network, it will eventually start trying to spread outside of your network thru the firewall. I have seen this first hand. So be sure to block outbound traffic on these ports.
08-14-2003 01:27 PM
How do I do this? I am a newbie and don't know much about the CLI. What statements must I type in in order to achieve this after I do the config t?
Thanks.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide