Zombie State: Curtailing Rouge Servers [Outbound Rules]

  • Hello:

    Was wondering what basic outbound rules or setup i should have in place to prevent servers and/or workstation from initiating traffic or calling home over non standard ports.

    Thank you.

  • If you don't trust your own LAN, what do you trust? If you want to block everything on your LAN from Internet access then do that via firewall rules or web proxy. Besides, you will find that malicious traffic will happily use tcp80,443 to talk because:

    • The bad traffic will get mixed into all the other http/s traffic and be harder to detect.
    • Standard ports are likely to be blocked off while tcp80,443 are almost always available.