LinuxQuestions.org
Visit Jeremy's Blog.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 07-24-2004, 07:23 AM   #1
Fuel
Member
 
Registered: Feb 2002
Location: Sweden, Skeldepth
Distribution: Slackware 10
Posts: 178

Rep: Reputation: 30
Smoothwall / Port 1


i see port 1 is open, should it be open ? what is it used for ?
http://www.grc.com/port_1.htm
..and port 0 <nil> ??

And whatabout if a cs server is behind the fw and i open port 27015 they still cant connect..

Last edited by Fuel; 07-24-2004 at 08:59 AM.
 
Old 07-24-2004, 10:20 AM   #2
Capt_Caveman
Senior Member
 
Registered: Mar 2003
Distribution: Fedora
Posts: 3,658

Rep: Reputation: 69
It's abnormal to have either of those ports open (esp port 0). What were the results of the GRC scan? They tend to make a big deal if ports aren't "stealthed", but there's actually a really big difference between a port being "closed" and a port being "open". If those two ports are indeed "open", use netstat -pantu or lsof -i to list what applications are listening on those ports.

As far as the cs server, do the same netstat command to see if the cs server daemon is even up and listening for connections, then try temporarily shutting of your firewall and see if you can connect.
 
Old 07-24-2004, 07:40 PM   #3
Fuel
Member
 
Registered: Feb 2002
Location: Sweden, Skeldepth
Distribution: Slackware 10
Posts: 178

Original Poster
Rep: Reputation: 30
well.. regarding the grc scan, port 0 & 1 seems to be sometimes closed and sometimes stealth, the netstat and lsof command didnt show anything either..

and the counter-strike issue, with fw unplugged players can connect as usual, with fw ( port forward any.ip:27015 --> server.ip:27015 ) they cant connect
 
Old 07-24-2004, 08:10 PM   #4
Capt_Caveman
Senior Member
 
Registered: Mar 2003
Distribution: Fedora
Posts: 3,658

Rep: Reputation: 69
well.. regarding the grc scan, port 0 & 1 seems to be sometimes closed and sometimes stealth
it's OK, as long as they're closed or "stealthed" and not open. Having ports listed as being "open" indicates that there is a service/daemon listening and accepting connections on that port (which for ports 0 & 1 would be abnormal). A "closed" port indicates that no services are accepting connections on that port and that the system sent back a reply of some sort (ie. icmp port unreachable message). A "stealthed" port simply means that no response at all was received. The difference between closed and stealthed is relatively minor and I tend to think is over-exagerated (often for monetary gain).

the netstat and lsof command didnt show anything either
Good sign as well.

and the counter-strike issue, with fw unplugged players can connect as usual, with fw ( port forward any.ip:27015 --> server.ip:27015 ) they cant connect
Could you post your firewall script, so we can see that rule in context with the rest of the firewall. Make sure to remove/obscure any public IPs. Also, could you describe your setup a little more clearly. How many computers, how are they connected, which one is the firewall, which one has the cs server?
 
Old 07-25-2004, 06:51 AM   #5
Fuel
Member
 
Registered: Feb 2002
Location: Sweden, Skeldepth
Distribution: Slackware 10
Posts: 178

Original Poster
Rep: Reputation: 30
www --> FW ( smoothwall ) --> switch --> servers

the CS server i just a windoze pc ( soon dedicated gnu/linux )

..by the way.. regarding port 0 .. could see in my phpinfo file today " Hostname:Port fuelman.domain.org:0 "

Last edited by Fuel; 07-25-2004 at 07:55 AM.
 
Old 07-25-2004, 02:38 PM   #6
Capt_Caveman
Senior Member
 
Registered: Mar 2003
Distribution: Fedora
Posts: 3,658

Rep: Reputation: 69
I believe the CS server uses port 27015 udp. By default Smoothwall will only forward the tcp port, not the udp one, so make sure that you specifically select the udp checkbox.

You might also want to consider making the CS server part of a DMZ (orange zone) if you are going to open up public access to it.

I'n not that familiar with PHP, but I'd guess the port 0 setting you are seeing in the phpinfo page is refering to the Apache API that PHP interacts with, not the actual port that Apache listens on (port 80).
 
Old 07-25-2004, 04:11 PM   #7
Fuel
Member
 
Registered: Feb 2002
Location: Sweden, Skeldepth
Distribution: Slackware 10
Posts: 178

Original Poster
Rep: Reputation: 30
gaaahhh.. udp * chewing on keyboard *

im familiar with PHP coding, but had nu clue about how the api works / port 0, thanks for info
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
port forwarding in smoothwall redi Linux - Distributions 10 01-09-2005 04:24 PM
Smoothwall Port Forwarding jonathen Linux - Networking 2 10-04-2004 09:18 AM
smoothwall port forwarding atomicx Linux - Networking 1 12-31-2003 11:38 PM
Smoothwall port forwarding pack Linux - Networking 1 04-15-2002 04:29 AM
IPCOP, Smoothwall - Port Forwarding. R4z0r Linux - Networking 0 01-23-2002 08:15 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 04:20 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration