Greetings,
I have noticed (thanks to the latest worm attacks) that Microsoft ports like RPC(135) and others are not defined or blocked. I have made those definitions manually and set rules to block them along with some of the worm ports like 123 and 8998.
The thing that confuses me is that it has been my understanding that ASL is "mostly closed" where everything is blocked and you must define the services you want to allow. If this is true then why do I have to define RPC udp/135 and then block it? Shouldn't everything but what I allow be blocked?
I ask these questions while my first hand perception tells me that my understanding explained above is incorrect somehow. If this is indeed the case does anyone have examples of catch-all rules that will close up all External to Internal traffic that was not explicitly defined as being allowed?
Thanks,
El Jefe
This thread was automatically locked due to age.