OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
From: ssardam (ssardamHSPH.HARVARD.EDU)
Date: Wed Apr 04 2001 - 17:33:16 CDT

  • Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]

    We deal with this quite a bit, this should take care of it:

    NetMeeting uses the following Internet Protocol (IP) ports:

       Port Purpose
       -------------------------------------
       389 Internet Locator Server [Transmission Control Protocol (TCP)]
       522 User Location Server (TCP)
       1503 T.120 (TCP)
       1720 H.323 call setup (TCP)
       1731 Audio call control (TCP)
       Dynamic H.323 call control (TCP)
       Dynamic H.323 streaming [Realtime Transport Protocol (RTP) over
    User Datagram Protocol (UDP)]
    To establish outbound NetMeeting connections through a firewall, the
    firewall must be configured to do the following:

    * Pass through primary TCP connections on ports 522, 389, 1503, 1720
    and 1731.
    * Pass through secondary UDP connections on dynamically assigned
    ports (1024-65535).
    NOTE: Some firewalls are capable of passing through TCP connections
    on specific ports, but are not capable of passing through secondary UDP
    connections on dynamically assigned ports. When you establish
    NetMeeting connections through these firewalls, you are unable to use
    the audio features of NetMeeting.

    In addition, some firewalls are capable of passing through TCP
    connections on specific ports and secondary UDP connections on
    dynamically assigned ports, but are not capable of virtualizing an arbitrary
    number of internal IP addresses, or are not capable of doing so
    dynamically. With these firewalls, you are able to establish NetMeeting
    connections from computers inside the firewall to computers outside the
    firewall and you are able to use the audio features of NetMeeting, but you
    are unable to establish connections from computers outside the firewall
    to computers inside the firewall.

    The H.323 call setup protocol (over port 1720) dynamically negotiates a
    TCP port for use by the H.323 call control protocol. Also, both the audio
    call control protocol (over port 1731) and the H.323 call setup protocol
    (over port 1720) dynamically negotiate User Datagram Protocol (UDP)
    ports for use by the H.323 streaming protocol, called the real time protocol
    (RTP). In NetMeeting, two ports are determined on each side of the
    firewall for audio and video streaming. These dynamically negotiated
    ports are selected arbitrarily from all ports that can be assigned
    dynamically.

    NetMeeting directory services require either port 389 or port 522,
    depending on the type of server you are using. Internet Locator Servers
    (ILSs), which support the lightweight directory access protocol (LDAP) for
    NetMeeting 2.0 or later, require port 389. User Location Servers (ULSs),
    developed for NetMeeting 1.0, require port 522.

    >===== Original Message From Focus on Microsoft Mailing List
    <FOCUS-MSSECURITYFOCUS.COM> =====
    >Hi there All,
    >
    >I am looking for a way to bind services to only
    >specific IP numbers on a multihomed NT machines (NT4 and 2000).
    >
    >the idea is to have two interfaces on the NT box one for administration
    >purposes and one for production.
    >
    >what I would like to do is to use some services ( say PC-anywhere )
    >that will only bind to the IP number of the administration card.
    >
    >any one knows if I can do that ??
    >
    >TIA...
    >
    > Reuven Twito
    >
    > Chief technologies officer
    > Spider Solution LTD.
    > Tel: +972-3-576-6980
    > mobile: +972-50-641549
    > Fax: +972-3-751-3626
    > 06 Ha'chilazon Street
    > Ramat Gan 52522, Israel
    > E-mail: reuvenspiderservices.com