republican-creole
Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Up and Running » Security » Security » Closed vs. Filtered
Search Topic:
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Post a:
Post a:
GWF's, useless logs, and abuse desks. »
« ZoneAlarm TrueVector Device Driver  
AuthorAll Replies


Randy Bell
Premium
join:2002-02-24
Santa Clara, CA

reply to Marilla
Re: Closed vs. Filtered

The classic discussion at DSLR was done in this old thread:

Closed vs Stealthed Ports
»Closed vs Stealthed Ports

but it is quite long, I warn you .. yet very informative and interesting.
--
"But now abide faith, hope, love, these three; but the greatest of these is love." (1 Cor. 13:13)


Marilla
I Am My Own Arbiter
Premium
join:2002-12-06
Belpre, OH

reply to Maven
Someone may correct me on specifics... as nit-picky as I can be, I'm not always that great on exact wording... that said:

As far as I understand it, 'Closed' and 'Filtered' aren't really directly related...

Closed means that no daemon/service is configured to respond on the port in question on a specific host.

Filtered means that there is a firewall somewhere which is 'intercepting' and dropping communications for a port. Actually, you don't so much filter a PORT as you filter datagrams based on whatever the rules are... and it's entirely possible that the 'rules' can be "drop all packets for this port" or "drop all packets EXCEPT those for this port"

The reason I say they aren't neccesarily directly related is this: It's entirely possible for a port to be OPEN, yet filtered. In fact, that's one of the greatest reasons to have a firewall in the first place: To enable a service (such as file sharing) to be available on your private network, but to have connections from outside to that service 'filtered' such that they do not get through.

Or.. umm.. something like that!

So, to answer your last question: If ALL of the ports are truly closed, then it would seem there isn't really a need for them to be filtered, too... but.. there's justa little more, because I mentioned a THIRD possibility above: Dropped.

When a port is 'closed', say port 80, and I try to connect to a computer on that port, the computer in question usually sends back an instant reply saying, "Hey, I don't have any service running on that port!" That's the normal behavior on a 'closed' port.

When communications to that port are "filtered" or "dropped", though... that "there's nothing here" response never gets sent. This is usually what some online tests mean when they say a port is 'stealthed', and it is a little better than simply being 'closed', because it forces a port scan to wait for a timeout before it can declare the port responding or not.
Forums » Up and Running » Security » SecurityGWF's, useless logs, and abuse desks. »
« ZoneAlarm TrueVector Device Driver  


Sunday, 29-Nov 14:50:36 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.
page compression OFF
Most commented news this week
· [124] Time Warner Cable Fires Broadside At Broadcasters
· [112] New AT&T Ad Campaign Hits Back At Verizon
· [96] Apple Joins AT&T Verizon Snark Fest
· [87] New Bill Takes Aim At Higher Verizon ETFs
· [80] TiVo Sees Record Customer Losses
· [77] Weekend Open Thread
· [76] Verizon CEO: Hulu Will Be Dead Soon
· [69] In-Flight Internet Headed For Bumpy Landing?
· [63] Thanksgiving Open Thread
· [40] EFF Wages War On Fine Print
Most people now reading
· Is Easynews down? [Filesharing Software]
· Are GPS's better today? [General Questions]
· Windows 7 boot manager editing questions [Microsoft Help]
· Grey Cup on the Web? [Canadian Chat]
· [Newsgroups] Newzleech down? [Filesharing Software]
· 3.x Feral Druid - Bear Tanking Guide [World of Warcraft]
· Idiotic neighbour [Canadian Chat]
· Surfers beware !!! [TekSavvy]
· [How to] Install Asterisk on an Asus WL-520GU router [VOIP Tech Chat]