Web Server forum
Back To The Forum Home!Search!Private Messaging System

This is Interesting: Free IT Magazines Now Free shipping to   
Web Server Talk Web Server Talk > Server Security > Microsoft Security > Firewall test




  Last Thread   Next Thread Next
  Show Printable Version Email this Page Subscribe to this Thread      Post New Thread    Post A Reply      

    Firewall test  
Mark G


View Ip Address Report This Message To A Moderator Edit/Delete Message


 
01-14-05 07:49 AM

Hi All,
I ran the 'ShieldsUp!' firewall test from www.grc.com. How can I tell if the
test has reached my PC's ports itself but my ISP? I'm connected to internet
via Zyxel adsl router. Test performed show most ports as 'closed' state,
three ports as 'stealth', HTTP and FTP ports are 'open'.
Using XP SP2 Home Ed. since 2002, Win Firewall enabled. No trojan or virus
infection before.   Thanks.





[ Post a follow-up to this message ]



    Re: Firewall test  
SimonH


View Ip Address Report This Message To A Moderator Edit/Delete Message


 
01-14-05 12:51 PM

Hello Mark,

Shields up will use the IP address that it detects when looking at your http
request headers i think.

This will more than likely be that of your modem or router.

This is typically what you want. However, if you want to make sure, look
at the IP address shields up says it is probing and then compare it to the
IP address of your modem or router.

I'm pretty sure youre getting the correct results. The IP scanned will be
"yours" even if it was assigned to you dynamically when you connected to
your isp

Simon

> Hi All,
> I ran the 'ShieldsUp!' firewall test from www.grc.com. How can I tell
> if the
> test has reached my PC's ports itself but my ISP? I'm connected to
> internet
> via Zyxel adsl router. Test performed show most ports as 'closed'
> state,
> three ports as 'stealth', HTTP and FTP ports are 'open'.
> Using XP SP2 Home Ed. since 2002, Win Firewall enabled. No trojan or
> virus
> infection before.   Thanks.







[ Post a follow-up to this message ]



    Re: Firewall test  
N. Miller


View Ip Address Report This Message To A Moderator Edit/Delete Message


 
01-14-05 12:51 PM

In article <49B13DED-C253-4936-BE56-42AE5F13CE65@microsoft.com>, =?Utf-8?B?
TWFyayBH?= says...

> I ran the 'ShieldsUp!' firewall test from www.grc.com. How can I tell if t
he
> test has reached my PC's ports itself but my ISP? I'm connected to interne
t
> via Zyxel adsl router. Test performed show most ports as 'closed' state,
> three ports as 'stealth', HTTP and FTP ports are 'open'.
> Using XP SP2 Home Ed. since 2002, Win Firewall enabled. No trojan or virus
> infection before.   Thanks.

There are two steps to take. Step one is to check your Zyxel configuration
page to see what IP address it is getting from your ISP. Step two is to
check the GRC web page when you run the test; what IP address does it say
that it is testing? If the two are the same, Shields Up! is testing your
router.

If your router is being tested, you want to double check the remote
administration setting. That should be disabled in most cases; that HTTP and
FTP are showing open suggests that your Zyxel is open to configuration from
the Internet side of the router (if, indeed, it is the router that Shields
Up! has probed). But those could also be the result of your ISP running a
caching proxy; so do the checks to see which IP address is being probed.

The GRC site operates news groups similar to this one; but you can't access
them with a web browser, as you have done here. How do I know you used a
browser? By checking your posting headers:

X-Newsreader: Microsoft CDO for Windows 2000

For GRC, fire up MS Outlook Express (unless you have a preferred news
client; I prefer Super Gravity) and set up an account. Use "news. grc.com"
for the server name. For the user name and password, use the exact same
string, preferably 12 characters, or more. Alphanumeric mix; something like:

User Name: xYzZy1zN7Aw0R6
Password:  xYzZy1zN7Aw0R6

There is a reason for that, as explained here:

http://www.imilly.com/noregrets.htm

After your client connects to the server, you will be presented with a list
of groups. For this problem you should choose, "grc.shieldsup". You will
find a lot of helpful people on that site, and most will be more
knowledgeable than the average in this group.

Also, did you know that you can access these groups with a news client? Just
set the server name as, "msnews.microsoft.com". No user name and password
combination is needed on the MSFT NNTP servers. Once connected you will be
presented with a humongous list of groups. For this group you would
subscribe, "microsoft.public.security".

You can have multiple NNTP server accounts in most news clients; even in MS
Outlook Express.

It is recommended that you not use your normal email address for the email
address entry for news posts; spammers and viruses scan posting headers to
pull email addresses for their own ends. I recommend something with an RFC
2606 reserved domain, such as: <don't.spam@me.invalid>. For the MSFT groups
I just use the same default that MSFT puts in place on the web site. If you
like, you can set a "Reply-To:" email address, but even there, use a
disposable email account, not your main email account. You can test mine by
using the "Reply to author" button (or whatever it may be labeled). Oh, and
mine is not to be altered; what you see works, making any changes breaks it.

--
Norman
~Win dain a lotica, En vai tu ri, Si lo ta
~Fin dein a loluca, En dragu a sei lain
~Vi fa-ru les shutai am, En riga-lint





[ Post a follow-up to this message ]



    Re: Firewall test  
Karl Levinson, mvp


View Ip Address Report This Message To A Moderator Edit/Delete Message


 
01-14-05 12:51 PM

Enable logging of blocked and/or accepted packets on your firewall and/or
router and watch the log.


"Mark G" <MarkG@discussions.microsoft.com> wrote in message
news:49B13DED-C253-4936-BE56-42AE5F13CE65@microsoft.com...
> Hi All,
> I ran the 'ShieldsUp!' firewall test from www.grc.com. How can I tell if
the
> test has reached my PC's ports itself but my ISP? I'm connected to
internet
> via Zyxel adsl router. Test performed show most ports as 'closed' state,
> three ports as 'stealth', HTTP and FTP ports are 'open'.
> Using XP SP2 Home Ed. since 2002, Win Firewall enabled. No trojan or virus
> infection before.   Thanks.







[ Post a follow-up to this message ]



    RE: Firewall test  
Mark G


View Ip Address Report This Message To A Moderator Edit/Delete Message


 
01-14-05 10:53 PM

Thanks Simon, Norman and Karl.
I really appreciate your help.


"Mark G" wrote:

> Hi All,
> I ran the 'ShieldsUp!' firewall test from www.grc.com. How can I tell if t
he
> test has reached my PC's ports itself but my ISP? I'm connected to interne
t
> via Zyxel adsl router. Test performed show most ports as 'closed' state,
> three ports as 'stealth', HTTP and FTP ports are 'open'.
> Using XP SP2 Home Ed. since 2002, Win Firewall enabled. No trojan or virus
> infection before.   Thanks.





[ Post a follow-up to this message ]



    RE: Firewall test  
Mark G


View Ip Address Report This Message To A Moderator Edit/Delete Message


 
01-17-05 10:56 PM

According with the results from IP2 small program
(http://www.keir.net/ip2.html  thanks to Robert Wycoff), Shields Up!
is testing my dsl Zyxel router since my LAN address is not the same as my
WAN one (which changes every time I turn my router on). I can't change
router's configuration due to can't access to it (my ISP manages the
password access) so I guess HTTP, Telnet and FTP ports are opened in the
router by default.
This suggest I'm protected behind a NAT router, question is, do
I still need to install one third party firewall for complete security? Am I
vulnerable to attacks from outside?

Thanks

"Mark G" wrote:

> Hi All,
> I ran the 'ShieldsUp!' firewall test from www.grc.com. How can I tell if t
he
> test has reached my PC's ports itself but my ISP? I'm connected to interne
t
> via Zyxel adsl router. Test performed show most ports as 'closed' state,
> three ports as 'stealth', HTTP and FTP ports are 'open'.
> Using XP SP2 Home Ed. since 2002, Win Firewall enabled. No trojan or virus
> infection before.   Thanks.





[ Post a follow-up to this message ]



    Sponsored Links  




 





   All times are GMT. The time now is 10:49 AM.      Post New Thread    Post A Reply      
  Last Thread   Next Thread Next


Most Popular forums 

Forum Jump:
Rate This Thread:

Forum Rules:
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
HTML code is OFF
vB code is ON
Smilies are ON
[IMG] code is OFF
 

Back To The Top
Home | Usercp | Faq | Register