next up previous
Next: Inbound port scan Up: Firewall audit for Ottawa Previous: spam relaying

Outbound port scan

A scan of all services (protocols: TCP and UDP, all ports) was done.

An attempt was made to connect to the internal address of the firewall, the external address of the firewall, and to a random node on the Internet. This test was simulating an internal person attempting to make an outbound connection. I.e. connect from the Private Network to the Public Network.

The following port was found to respond on the internal address of the firewall: TCP port 25.

No other TCP or UDP traffic was found to flow through the firewall. This was done by observing the network on both sides of the firewall.

This port is the SMTP port and is therefore within keeping of the security policy.

Based upon the stated security policy, TCP Port 143 (IMAP) was expected to be respond as well, but it did not.



Michael C. Richardson
1998-11-15