| |
Application Compatibility
Firstly, the firewall will only affect traffic to
and from off-campus. Any traffic between on-campus hosts will
not be affected by the firewall in any way.
What applications WILL work
(which ports are open) in the Mostly Closed (MC) firewall?
- AIM and AIM File Transferring - If you are
having problems getting AIM Filesharing to work with friend who is
off-campus, try changing the port in AIM's File Transfer Preferences to
"6891".
- Battlenet - Diablo, Diablo 2, StarCraft,
WarCraft 2, WarCraft 3. (TCP Ports 4000, 6112; UDP Port 6112)
- FTP / SFTP (TCP/UDP Ports 20, 21, 115)
- H.323 - Video Conferencing applications such as
MS Netmeeting. (TCP Ports 389, 522, 1503, 1720, 1731 among other things)
- HTTP / HTTPS - Web surfing and Web
serving. (TCP/UDP Ports 80, 443)
- IMAP / secure IMAP - Mail applications such as
MS Outlook. (TCP/UDP Ports 143, 220?, 585?, 993)
- MSN / Windows Messenger Chat, File
Transferring, and Application/Whiteboard Sharing (Ports 1503, 6891) -
Only one file transfer at a time will work.
- Net2Phone - Internet Phone application; set
port 9084 as the additional port. (UDP Port 6801, TCP/UDP
Port 9084)
- PC-Telephone - Internet Phone
application. (TCP/UDP Port 9084)
- POP3 / Secure POP - Mail applications such as
MS Outlook. (TCP/UDP Ports 109, 110, 995)
- SMTP - Mail applications such as MS
Outlook. (TCP/UDP Port 25)
- SSH - Secure Shell Client and Server (TCP/UDP
Port 22)
- Sony PlayStation 2 (TCP Ports 10070 - 10080,
UDP Port 10070)
- Telnet (TCP/UDP Port 23)
- Video Phone - Sorenson Videophone 200 (TCP/UDP
Ports 15328 - 15348)
What applications WON'T work
in the Mostly Closed (MC) firewall?
- Anything inbound traffic that requires ports
other than the ones listed above
- CounterStrike server
- EverQuest
- MSN / Windows Messenger AV (for example:
Voice/Video Communication)
- MSN Zone
- Some filesharing programs may see restrictions
similar to AIM Filesharing; they may not work with another host who is
behind a different firewall, unless you can specify an open port number
to use.
- Windows XP Remote Assistance
Known restrictions of the Fully Closed (FC)
firewall setting:
- Any incoming connections that don't have a
corresponding outgoing transaction will be denied. For
example, a machine behind FC cannot be an ssh server for machines off
campus (however, this is possible using the campus VPN).
This includes both TCP and UDP requests.
- For filesharing programs (such as Bearshare,
Direct Connect, Kazaa, Blubster/Piolet, WinMX, etc), downloading files
from any on or off-campus host is unaffected. Uploading files
to an off-campus host varies from application to application.
Some applications seem to allow uploads to any hosts, others behave
similarly to AIM file transferring. Some filesharing
programs, such as Direct Connect, may not function properly because
they require a minimum number of files to be shared.
- Running any server, such as a web server, FTP
server, ssh server, etc, will not work to off-campus hosts (unless the
VPN is used).
- Quicktime requires running an "autoconfigure"
to work.
- IRC may be greatly affected. Some
chat functionality is impaired, Ident fails (so some external servers
may not allow an FC client to connect), file transferring is impaired.
- Windows XP Remote Assistance will not work.
|
|