Restricting source port across sites

May 11, 2006 0 Replies
Restricting source port across sites open original image

Hi,



I have to deal with a firewall policy where they *insist* on only allowing comminucation to AND FROM specific ports across sites. This also includes the infamous DCOM port 135. Which is ironic, bacause I'm beginning to think this cant be done. (Which is probably the intention!)



I know that RPC can be configured to only use a certain port range (

formatting link
)



But AIUI, this range only applies to the temporary server port that is created by the RPC port mapper on the destination machine. It does not apply to the ehpemeral address range on the client machine. So the from port could still be any port in the ephemeral range.



A bodge (that might really break the client box) would be to set \\HKLM\\SYSTEM\\CurrentControlSet\\Services\\Tcpip\\Parameters\\MaxUserPorts to a low value. (Shame there is no MinUserPorts setting)



And possibly reduce TcpTimesWaitDelay to 10 seconds or so, so ports get freed up quciker??



Lordy



Join the Discussion

Have something to add? Share your thoughts — no account required.

Didn't find your answer?

Ask the community — no account required