Reseller Hosting, Shared Hosting, Dedicated Hosting by Vortech Inc.

Go Back   Reseller Hosting, Shared Hosting, Dedicated Hosting by Vortech Inc. > >>Network Information & News and Announcements > Network / Server Status
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Network / Server Status Please check often for network / Server updates here!

Reply
 
Thread Tools Display Modes
  #1  
Old 05-11-2003, 12:31 PM
alan
Guest
 
Network Modification "LOOK"

Starting on Monday May 12th I will be making some security changes to our cisco firewall. We will only be allowing certain ports as well as protocols to enter the network. I am compiling the ACL with the other admins as well as psoft to get a current list of the ports to leave open, i.e. inbound as well as outbound, double-checking that I didn't miss any. I will be running the configuration tonight on my own cisco rack @ home to ensure capadibility. If however during the course of the modifications you notice that a certain port was missed you can email support@vortechhosting as we will be monitoring this throughout the upgrade if we missed one. As I will be at the console port during configuration, there should only be a momentary reload of the router as I save the config to flash.

Just submit the port as well as the service you need and i can fix it immediatly. i.e.

Examples:

port needed:22
Reason/Service:ssh

port needed:23
Reason/Service:telnet
Reply With Quote
  #2  
Old 05-11-2003, 10:09 PM
bfriended bfriended is offline
Vortech Inc. Customer
Vortech Inc. Customer
 
Send a message via AIM to bfriended
OK, I don't know what these ports are and what I should be checking. Please steer me in the right direction
Reply With Quote
  #3  
Old 05-12-2003, 07:49 AM
alan
Guest
 
I should have most of them covered, so really nothing for you to do. If you see a service not "co-operating" just submit a ticket . As soon as we implement this we will being doing port scans to check availabilty throughout the network and adjusting where necessary.
Reply With Quote
  #4  
Old 05-13-2003, 08:08 AM
MEELAN's Avatar
MEELAN MEELAN is offline
Vortech Inc. Customer
Vortech Inc. Customer
 
Location: Roaming
I am experiencing a problem with my FTP client. May be related to thise thread.
When I do FTP with ws_FTP pro (after establishing FTP sucessfully) it tries to open the connection using some other random port numbers like 4950, 4982 etc. But, since they are already "BLOCKED" connection fails.
It takes lt of time to completes the FTP commands and uploading due to this.
---------------
WINSOCK.DLL: WinSock 2.0
WS_FTP Pro 6.51T 2000.05.15, Copyright © 1992-2000 Ipswitch, Inc.
- -
connecting to 216.157.129.232:21
Connected to 216.157.129.232 port 21
220 ProFTPD 1.2.8 Server (Main FTP Server) [unix5.hsphere.cc]
USER <USER_NAME>
331 Password required for niroshav.
PASS (hidden)
230 User <USER_NAME> logged in.
PWD
257 "/" is current directory.
Host type (I): UNIX (standard)
PASV
227 Entering Passive Mode (216,157,129,232,19,86).
connecting to 216.157.129.232:4950
- -
connecting to 216.157.129.232:4950
! Connection failed 216.157.129.232 - error 10051
! connect: error 0
PORT 203,94,94,40,5,220
200 PORT command successful
LIST
150 Opening ASCII mode data connection for file list
Received 1084 bytes in 0.2 secs, (52.63 Kbps), transfer succeeded
226 Transfer complete.
PWD
257 "/" is current directory.
PASV
227 Entering Passive Mode (216,157,129,232,19,118).
connecting to 216.157.129.232:4982
- -
connecting to 216.157.129.232:4982
! Connection failed 216.157.129.232 - connection timed out
! connect: error 0
PORT 203,94,94,40,5,224
200 PORT command successful
LIST
150 Opening ASCII mode data connection for file list
Received 1084 bytes in 0.1 secs, (66.67 Kbps), transfer succeeded
226 Transfer complete.

--------------

PLEASE SEE THE ERRROR LINES ABOVE

Is there any others experiencing the same?
__________________
meelan ;-)
Reply With Quote
  #5  
Old 05-13-2003, 08:17 AM
Brangwyn Brangwyn is offline
T3CHN0 STUD
Vortech Inc. Customer
 
Location: New Zealand (Wellington)
Try turning off PASV mode, though if you have a NAT you may not be able to connect at all then.

I suspect your right about the slowdowns though being related to the port changes on the router, no doubt Alan will follow this up.

Just wondering which direction were the ports blocked alan ? outgoing ? (which I guess could cause this problem) or just incoming which may be all you probably need anyway unless you don't trust your internal network too well (which may be the case if you don't have full control of the segment I guess).

Last edited by Brangwyn : 05-13-2003 at 08:29 AM.
Reply With Quote
  #6  
Old 05-13-2003, 09:26 AM
payne payne is offline
BANNED
Banned
 
Location: I LIVE IN FAG VILLE
The Ports I know I need right now

port:10000 service:webmin - web aministration interface (VERY IMPORTANT)
port:9999 service:Urchin
port:21 service:ftp
port:22 service:ssh
port:22(UDP) service:ssh
port:25 service:smtp
port:53 service:dns
port:53(UDP) service:dns
port:79 service:finger
port:80 service:apache
port:8080 service:tomcat
port:110 serviceop3
port:110(UDP) serviceop3
port:119 service:news
port:123 service:nettime
port:143 service:imap2
port:160-161(UDP) service:snmp
port:194 service:irc
port:220 service:imap3
port:220(UDP) service:imap3
port:389 service:ldap
port:443 service:apache ssl
port:443(UDP) service:apache ssl
port:540 service:uucp
port:1220 service:darwin streaming server admin
port:2401 service:cvs
port:2401(UDP) service:cvs
port:554 service:darwin ss
port:3306 service:mysql
port:3306(udp) service:mysql
port:7070 service:darwin ss
port:6970-6999(UDP) service:darwin ss
port:8000 sercice:darwin ss
Reply With Quote
  #7  
Old 05-13-2003, 09:27 AM
payne payne is offline
BANNED
Banned
 
Location: I LIVE IN FAG VILLE
damn smileys
Reply With Quote
  #8  
Old 05-13-2003, 09:40 AM
Brangwyn Brangwyn is offline
T3CHN0 STUD
Vortech Inc. Customer
 
Location: New Zealand (Wellington)
I didn't think pop3 used UDP at all.

Reply With Quote
  #9  
Old 05-13-2003, 10:26 AM
admin's Avatar
admin admin is offline
Vortech Inc. Owner
Owner
 
Location: Orlando FL
Send a message via ICQ to admin
payne, are you a colo customer? If so just send a ticket to support@vortechhosting.com we can set these for your IP address of your server only or leave you wide open ether way..
__________________
Brad Pugh
http://www.vortechhosting.com
------

Local System/Network Monitor
http://nagios.hsphere.cc/
Login:guest Pass:guest
XML FEED http://nagios.hsphere.cc/feed.xml
------

My Other Life:
Reply With Quote
  #10  
Old 05-13-2003, 11:26 AM
chrisdag
Guest
 
Secure IMAP seems to be blocked now

SSL access to IMAP mailserver stopped working after 8am today!

IMAPv4 over SSL uses port 993

Will file a support ticket now.
Reply With Quote
  #11  
Old 05-13-2003, 12:12 PM
Wonderer Wonderer is offline
Vortech Inc. Customer
Vortech Inc. Customer
 
Location: Portland, Oregon
Question and this firewall. Can i rightly assume that your using the PIX Series or better? If so i fail to see why passive ftp would be an issue as long as your utilizing SPI. While posting the config would be bad for obvious reasons, could you please verify if you are using SPI?
__________________
http://www.wonderer.net/
Reply With Quote
  #12  
Old 05-13-2003, 12:59 PM
MEELAN's Avatar
MEELAN MEELAN is offline
Vortech Inc. Customer
Vortech Inc. Customer
 
Location: Roaming
Brangwyn:
Turning off PASSIVE transfer helped me to get rid of the problem.
Thankz
__________________
meelan ;-)
Reply With Quote
  #13  
Old 05-14-2003, 08:10 AM
Brangwyn Brangwyn is offline
T3CHN0 STUD
Vortech Inc. Customer
 
Location: New Zealand (Wellington)
Glad that worked for you Lankan
Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Network Solutions - Where did the "Manage Host Servers" option go? tkraffty Chit Chat Public 3 07-01-2004 03:37 AM
Logging in to admin account using "client login" method... antic Chit Chat Public 4 05-25-2004 09:38 PM


All times are GMT -5. The time now is 08:57 AM.


Powered by vBulletin Version 3.5.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Vortech Inc. ©2005
Page generated in 0.72944 seconds with 21 queries
[Output: 94.91 Kb. compressed to 87.09 Kb. by saving 7.82 Kb. (8.24%)]