Navigation

    Netgate Discussion Forum
    • Register
    • Login
    • Search
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search

    Block TCP port 445 at network edge?

    General pfSense Questions
    3
    4
    57
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • V
      VirtuousVigor last edited by VirtuousVigor

      Just would like to know if it is firewall best practice to have an explicitly defined WAN rule to block all traffic targeting destination port 445 on internal private hosts?

      Is this already accounted for by these default config rules:

      Annotation 2020-05-11 145921.png

      Based on this info -> https://www.grc.com/port_445.htm

      1 Reply Last reply Reply Quote 0
      • chpalmer
        chpalmer last edited by

        ISP's generally these days do block port 445.

        Yes if you are worried put a block from all to port 445 on your LAN interface.

        http://attrition.org/errata/charlatan/steve_gibson/

        445rule.jpg

        1 Reply Last reply Reply Quote 1
        • Rico
          Rico LAYER 8 Rebel Alliance last edited by

          Only what is explicitly allowed via firewall rules will be passed.
          Per default there are no WAN rules, so any incoming WAN traffic is denied.

          -Rico

          chpalmer 1 Reply Last reply Reply Quote 1
          • chpalmer
            chpalmer @Rico last edited by

            @Rico Thanks.. I saw LAN when I read the OP the first time.

            ^^ what Rico said. :)

            1 Reply Last reply Reply Quote 0
            • First post
              Last post

            Products

            • Platform Overview
            • TNSR
            • pfSense Plus
            • Appliances

            Services

            • Training
            • Professional Services

            Support

            • Subscription Plans
            • Contact Support
            • Product Lifecycle
            • Documentation

            News

            • Media Coverage
            • Press
            • Events

            Resources

            • Blog
            • FAQ
            • Find a Partner
            • Resource Library
            • Security Information

            Company

            • About Us
            • Careers
            • Partners
            • Contact Us
            • Legal
            Our Mission

            We provide leading-edge network security at a fair price - regardless of organizational size or network sophistication. We believe that an open-source security model offers disruptive pricing along with the agility required to quickly address emerging threats.

            Subscribe to our Newsletter

            Product information, software announcements, and special offers. See our newsletter archive to sign up for future newsletters and to read past announcements.

            © 2021 Rubicon Communications, LLC | Privacy Policy