Welche anderen Ports sollte ich blockieren, um die Serversicherheit zu maximieren? PS mit IPTABLES

784
JoyIan Yee-Hernandez

Ich habe die Ports 80, 9001, 9080 blockiert. Welche anderen Ports sollten zur Maximierung der Sicherheit gesperrt werden?

PS: Es ist ein Sterneserver / eine PBX

Entschuldigung: Neuer Systemadministrator hier :)

Vielen Dank!

2

1 Antwort auf die Frage

5
laurent

The best is to block all the ports (iptables default to DROP) and open only what you need (probably port 5060 at least for your asterisk server). If you need to administer asterisk from outside, port 80 needs to be open if you administer it from a web browser or port 22 if you use ssh.

Update:

For Asterisk, I don't think you need other ports open and even not sure you need 5060 open. If you only receive calls coming through your voip provider (with a trunk) there is no need to open 5060.

You need to open 5060 if you have extensions (or another Voip PBX) connecting from the internet but I don't recommend that if you can avoid it. You can use a VPN instead.

Tbh I think better using asterisk in the LAN (behind a router/server with NAT and firewall), without direct connection to internet. In this case, your internet facing server (or router) has to port-forward the RTP ports range you use in asterisk (8000-10001 possibly) to your asterisk server. You need also to port-forward 5060 if you receive new connections on it.

Obs: a new call received from a trunk (DID for example) is not a new connection to 5060 because the connection to your voip provider using the trunk is initiated by asterisk so it is in RELATED or ESTABLISHED state for the firewall and should be already authorized by the router firewall (if not, you probably have no internet in the LAN).

Vielen Dank für den Input laurent. Nun, wir machen einen Tunnel via SSH. Also, ja, Port 80 ist schon gesperrt, zu viele Hacker gehen herum. LOL..jedoch mehr Ports, auf die ich achten sollte? JoyIan Yee-Hernandez vor 12 Jahren 0
Beliebige Datenbankanschlüsse? 1433 und 1434 wenn MS SQL SERVER verwendet wird? Dave vor 12 Jahren 0
Aktualisierte Antwort mit weiteren Kommentaren zur Sicherheit laurent vor 12 Jahren 0