PIX question - Is New Internet Worm blocked out of the box?
Am I right to assume that the handful of ports 69, 135, 139, 445 and 4444 are blocked by nature on the PIX? I have not expressly opened any of them as far as I can tell? I have looked around on the net and not found anyone talking about the PIX in conjunction with this worm. Thanks for you help.
Re: PIX question - Is New Internet Worm blocked out of the box?
These ports are blocked from outside to inside (inbound traffic) interfaces only. They are not blocked from inside to outside (outbound traffic). If you have an infected PC on your network, it will eventually start trying to spread outside of your network thru the firewall. I have seen this first hand. So be sure to block outbound traffic on these ports.
We have configured the outside and inside Interface with official ipv6 adresses, set a default route on outside Interface to our router, we also have definied a rule , which also gets hits, to permit tcp from inside Interface to any6.
In Syslog I also se...