Safe to permit in firewall?

R

Ramesh

HI,

i recently installed the Kerio Firewall software. Once I connect to the
Internet thro DSL, the following two boxes keeps popping up .. I am not sure
if they are safe to permit or not ..
Could you someone please confirm?

(1)
Direction: incoming
Local Point: 125.22.144.41, port microsoft-ds [445]
Adapter: N/A
Remote Point: BTNL-TN-DSL-dynamic-108.74.22.125.touchtelindia.net
[125.22.74.108], port 1867
Protocol: TCP

Application path: NETBIOS
Description: Microsoft File and Printer Sharing
File version: (null)
Created: N/A
Modified: N/A
Accessed: N/A

RuleId = 1342177289

(2)
Direction: incoming
Local Point: 125.22.144.41, port epmap [135]
Adapter: N/A
Remote Point: BTNL-TN-DSL-dynamic-108.74.22.125.touchtelindia.net
[125.22.74.108], port ingreslock [1524]
Protocol: TCP

Application path: c:\WINDOWS\system32\svchost.exe
Description: Generic Host Process for Win32 Services
File version: 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
Created: 2003/3/31, 12:00:00
Modified: 2004/8/3, 19:26:58
Accessed: 2006/7/25, 14:54:32

RuleId = 1342178097

Thanks for any help.

Ramesh
 
S

Steven L Umbach

Those are ports used in file and print sharing and you do not want to allow
traffic from the internet to try and connect to those ports.

Steve
 
P

Pop`

Ramesh said:
HI,

i recently installed the Kerio Firewall software. Once I connect to
the Internet thro DSL, the following two boxes keeps popping up .. I
am not sure if they are safe to permit or not ..
Could you someone please confirm?

(1)
Direction: incoming
Local Point: 125.22.144.41, port microsoft-ds [445]
Adapter: N/A
Remote Point: BTNL-TN-DSL-dynamic-108.74.22.125.touchtelindia.net
[125.22.74.108], port 1867
Protocol: TCP

Application path: NETBIOS
Description: Microsoft File and Printer Sharing
File version: (null)
Created: N/A
Modified: N/A
Accessed: N/A

RuleId = 1342177289

(2)
Direction: incoming
Local Point: 125.22.144.41, port epmap [135]
Adapter: N/A
Remote Point: BTNL-TN-DSL-dynamic-108.74.22.125.touchtelindia.net
[125.22.74.108], port ingreslock [1524]
Protocol: TCP

Application path: c:\WINDOWS\system32\svchost.exe
Description: Generic Host Process for Win32 Services
File version: 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
Created: 2003/3/31, 12:00:00
Modified: 2004/8/3, 19:26:58
Accessed: 2006/7/25, 14:54:32

RuleId = 1342178097

Thanks for any help.

Ramesh

Is there any reason for touchtelindia.net to be trying to contact you and
share files or printers on your computer? If not, then DENY them
permanently. If there is, and you KNOW WHO THEY ARE, and they are somehow
related to you, call them and ask them why they're doing that. Otherwise,
avoid them like the plague; they want to steal data from your system of
worse.

I suspect it's an intrusion attempt; deny them.

Pop
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top