"Bi-directional" ports

Jul 17, 2006 6 Replies

All, I have a group of "developers" who continually request ports to be opened "bi-directionally" on the firewalls. To me this indicates they have little knowledge of the essentials of how TCP works BUT I am in need of a best practice document which could explain why this is a bad thing.



TNX



Ask them why they need the ports open in both directions and to submit the actual protocols used.

The general rule is expose NOTHING unless there is a valid business reason for it.

I've not seen many valid reasons come from developers - if you really need something like that, put them in their own subnet, in a second DMZ, and then expose them.

Better ask them, what they exactly need and why.

Yours, VB.

Big issues are:

1) They do not know what they need or why. 2) Can't isolate traffic to an internal DMZ, they require access to internet as well as other DMZ's/networks through the enterprise. 3) They have no concept of traffic flows or basic IP concepts. No concept of source devices/applications initiating traffic on a known port, return traffic occuring on random high ports. Their requests typically involve opening the firewall on a given port from source to destination with all return traffic being allowed and then doing the reverse.

I guess I will have to teach a class in Basic TCP/IP concepts.......

Volker Birk wrote:

Do they need to know about traffic flows or basic IP concepts? Maybe they should tell what they're trying to achieve, in stead of telling how things should be done.

In my opinion thats the wordt thing an admin can happen: users who think they know...

My 2 cents.

Peter

That's the best way to handle it, I think. They should be asked what program are you wanting to use? For what purpose? To connect to whom?

These are very pointed questions that should be asked. It's the admin's bound duty to get detailed answers on why any ports should be open. You don't need a security audit team coming in and laying blame on *you* for opening up the company network to P2P & IM programs & that's how the domain server got the latest trojan du jour.

Most of these "social" programs can run on any port these days. Make the "devs" explain in detail why they are requesting what they are.

(Side note: This is to the original poster, not you, Peter...your post just provided a good place for me to jump in.)

My job is done ;-)

Peter

Join the Discussion

Have something to add? Share your thoughts — no account required.

Didn't find your answer?

Ask the community — no account required