republican-creole
Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Up and Running » Security » Security » Closed vs. Filtered
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Post a:
Post a:
GWF's, useless logs, and abuse desks. »
« ZoneAlarm TrueVector Device Driver  

Marilla
I Am My Own Arbiter
Premium
join:2002-12-06
Belpre, OH

Re: Closed vs. Filtered

Someone may correct me on specifics... as nit-picky as I can be, I'm not always that great on exact wording... that said:

As far as I understand it, 'Closed' and 'Filtered' aren't really directly related...

Closed means that no daemon/service is configured to respond on the port in question on a specific host.

Filtered means that there is a firewall somewhere which is 'intercepting' and dropping communications for a port. Actually, you don't so much filter a PORT as you filter datagrams based on whatever the rules are... and it's entirely possible that the 'rules' can be "drop all packets for this port" or "drop all packets EXCEPT those for this port"

The reason I say they aren't neccesarily directly related is this: It's entirely possible for a port to be OPEN, yet filtered. In fact, that's one of the greatest reasons to have a firewall in the first place: To enable a service (such as file sharing) to be available on your private network, but to have connections from outside to that service 'filtered' such that they do not get through.

Or.. umm.. something like that!

So, to answer your last question: If ALL of the ports are truly closed, then it would seem there isn't really a need for them to be filtered, too... but.. there's justa little more, because I mentioned a THIRD possibility above: Dropped.

When a port is 'closed', say port 80, and I try to connect to a computer on that port, the computer in question usually sends back an instant reply saying, "Hey, I don't have any service running on that port!" That's the normal behavior on a 'closed' port.

When communications to that port are "filtered" or "dropped", though... that "there's nothing here" response never gets sent. This is usually what some online tests mean when they say a port is 'stealthed', and it is a little better than simply being 'closed', because it forces a port scan to wait for a timeout before it can declare the port responding or not.

Randy Bell
Premium
join:2002-02-24
Santa Clara, CA

Re: Closed vs. Filtered

The classic discussion at DSLR was done in this old thread:

Closed vs Stealthed Ports
»Closed vs Stealthed Ports

but it is quite long, I warn you .. yet very informative and interesting.
--
"But now abide faith, hope, love, these three; but the greatest of these is love." (1 Cor. 13:13)
Forums » Up and Running » Security » SecurityGWF's, useless logs, and abuse desks. »
« ZoneAlarm TrueVector Device Driver  


Sunday, 29-Nov 21:27:13 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.republican-creole
page compression OFF
Most commented news this week
· [124] Time Warner Cable Fires Broadside At Broadcasters
· [112] New AT&T Ad Campaign Hits Back At Verizon
· [96] Apple Joins AT&T Verizon Snark Fest
· [87] New Bill Takes Aim At Higher Verizon ETFs
· [81] Weekend Open Thread
· [80] TiVo Sees Record Customer Losses
· [79] Verizon CEO: Hulu Will Be Dead Soon
· [69] In-Flight Internet Headed For Bumpy Landing?
· [63] Thanksgiving Open Thread
· [41] ICANN Slams DNS Redirection
Most people now reading
· Grey Cup on the Web? [Canadian Chat]
· Are GPS's better today? [General Questions]
· Is Easynews down? [Filesharing Software]
· [Newsgroups] Newzleech down? [Filesharing Software]
· Windows 7 boot manager editing questions [Microsoft Help]
· [ Classes] Druid tanking: rotation and glyphs [World of Warcraft]
· Surfers beware !!! [TekSavvy]
· Maximizing Rogue DPS for 3.1 [World of Warcraft]
· Considering Leaving Vonage, who should I Consider? [VOIP Tech Chat]