cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
390
Views
3
Helpful
2
Replies

Port 445 Question

fineospaul
Level 1
Level 1

CISCO-PIX-515E:

I am NOT exposing port 445 to the internet (as I have no need or disire to do so and am well aware of the security issues)

- but I have noticed that one of my DMZ hosts (an SSL VPN Server) is trying to pass 445 traffic internally -

so my question is...is it also considered to be bad practice to allow port 445 traffic between a DMZ host and an internal host?

Externally we ONLY allow port 443 to the DMZ Server in question.

2 Replies 2

Not applicable

I don't think there is any harm in this since systems on DMZ can't access internal hosts directly.

This is the case that you have the SSL VPN

Server configured for Windows Domain

authentication. It is trying to use either

port 139 (legacy) or port 445 (new) for

authenticating users with Domain Authentication.

I do the same thing with my VPN concentrator.

Review Cisco Networking products for a $25 gift card