Untangle Networks [home]


Go Back   Untangle Forums > General Forums > Networking

Closed Thread
 
LinkBack Thread Tools
Old 02-03-2009, 11:31 AM   #1 (permalink)
Untanglit
 
Join Date: Dec 2008
Location: NYC
Posts: 13
medallion is on a distinguished road
Exclamation Protocol Control blocking incorrect ports

I just spent days figuring out why our outside staff could not access our Filemaker server. Filemaker uses port 5003 and has been doing so for well over a decade or more.

I finally located in our Untangle reports that Protocol Control was wrongly associating port 5003 and port 53 with the predefined Soulseek and Xunlei P2P Protocols. I have all P2P protocols set to block. Why Xunlei should be associated with DNS port 53 is beyond me.

Please see attached Untangle report page.
Attached Images
File Type: png Untangle report-page590.png (169.8 KB, 16 views)
medallion is offline  
Old 02-03-2009, 11:48 AM   #2 (permalink)
Untangle Ninja
 
sky-knight's Avatar
 
Join Date: Apr 2008
Location: Phoenix, AZ
URLs submitted: 7
Posts: 9,951
sky-knight is on a distinguished road
Default

The reports don't indicate TCP vs UDP so you have to be careful here.

UDP 5003 is for filemaker, TCP is not. Just like UDP 53 is for DNS lookups where as TCP 53 is for DNS Zone transfers.

In any event people that bypass security protocols do so by ignoring the standards and doing what they want. So you have a protocol control rule that is blocking port 5003 and preventing filemaker from working?

This isn't a malfunction with the protocol control module, it's a bug that looks like filemaker. Turn off the offending rule.. sometimes you can't have it all!

However, if you have the policy manager. You could always create a second virtual rack, and route all traffic bound for your filemaker server into that second rack. Then, you could disable the problematic protocol control rule only within that context. Allowing your filemaker to work, while leaving the P2P rule in place for the rest of the network.
__________________
Intouch Technology
Rob Sandling, BS:SWE, MCP
Office: 480-272-9889
rob@intouchtechllc.com
sky-knight is online now  
Old 02-03-2009, 11:53 AM   #3 (permalink)
Untanglit
 
Join Date: Dec 2008
Location: NYC
Posts: 13
medallion is on a distinguished road
Default

Thank you Sky, your explanation makes perfect sense.
medallion is offline  
Old 02-03-2009, 02:13 PM   #4 (permalink)
Untanglit
 
Join Date: Dec 2008
Location: NYC
Posts: 13
medallion is on a distinguished road
Default

Quote:
Originally Posted by sky-knight View Post
The reports don't indicate TCP vs UDP so you have to be careful here.

UDP 5003 is for filemaker, TCP is not.
Actually I looked it up on Filemaker.com support and Filemaker does indeed use both TCP and UDP port 5003.
medallion is offline  
Old 02-03-2009, 03:51 PM   #5 (permalink)
Untangle Junkie
 
dmorris's Avatar
 
Join Date: Nov 2006
Location: San Mateo, CA
URLs submitted: 10
Posts: 6,694
dmorris is on a distinguished road
Default

this is probably just a false positive on the protocol control signature.

You can do as sky suggested or just disable the rules.

protocol control doesn't even look at the port - it scans all ports with the signatures
dmorris is online now  
Old 02-04-2009, 08:12 AM   #6 (permalink)
Untanglit
 
Join Date: Dec 2008
Location: NYC
Posts: 13
medallion is on a distinguished road
Default

Quote:
Originally Posted by dmorris View Post
this is probably just a false positive on the protocol control signature.

You can do as sky suggested or just disable the rules.

protocol control doesn't even look at the port - it scans all ports with the signatures
Where can I find detailed instruction on how to setup Policies? I tried to setup one up but it's not working. I want to make sure I'm doing correctly.
medallion is offline  
Old 02-17-2009, 11:13 AM   #7 (permalink)
Master Untangler
 
Join Date: Apr 2008
URLs submitted: 3
Posts: 106
JGrubbs is on a distinguished road
Default

We have noticed Protocol Control blocking some connections to OpenDNS, it looks like it is classifying these connections as Gaming. In the attached image you can see that is thinks these connections are World of Warcraft.
Attached Images
File Type: jpg ProtocolControl.jpg (20.9 KB, 7 views)
JGrubbs is offline  
Closed Thread

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 02:50 PM.


© 2010 Untangle, Inc. All Rights Reserved.   SEO by vBSEO 3.3.2