is it rational to close the 139 port



Hi,

strangely my netstat showed my 139 and 445 ports are open.

tcp 0 0 0.0.0.0:445 0.0.0.0:* LISTEN
tcp 0 0 0.0.0.0:139 0.0.0.0:* LISTEN

Do I need specify

-A INPUT -p tcp --dport 139 -j REJECT

in iptables?

For all INPUT has already set -P INPUT DROP, except open for 80, 443, 22,

BTW, why need allow ping? from outside?
59 # Allow ping
60 -A INPUT -p icmp -m icmp --icmp-type 8 -j ACCEPT

I know so little, thanks very much for your expilanation,

Best regards,


--
To UNSUBSCRIBE, email to debian-user-REQUEST@xxxxxxxxxxxxxxxx
with a subject of "unsubscribe". Trouble? Contact listmaster@xxxxxxxxxxxxxxxx
Archive: http://lists.debian.org/CAG9cJmmyF4Hi5aKjdzOX8NXew2LVbpNyu0aSDytCjZ9AsB961Q@xxxxxxxxxxxxxx



Relevant Pages

  • Re: Squid as default gateway in proxy mode.
    ... the console and ping. ... NAT only ICMP Echo Rep and Req so that i can at least ping outside ... control over traffic with IPtables firewall. ... To UNSUBSCRIBE, email to debian-user-REQUEST@xxxxxxxxxxxxxxxx ...
    (Debian-User)
  • RE: Reg : RHEL 5.0 Installatio
    ... To subscribe or unsubscribe via the World Wide Web, ... Subject: Reg: RHEL 5.0 Installatio ... Ping from yourself to yourself; ping localhost, ...
    (RedHat)
  • RE: TCP not working over ppp connection (WAS: 5th day using Linux...)
    ... * You say you can ping outside addresses? ... > installed modules: lsmod ... > after the initial install, ... > with a subject of "unsubscribe". ...
    (Debian-User)
  • RE: Reg : RHEL 5.0 Installatio
    ... Ping from yourself to yourself; ping localhost, ... Subject: Reg: RHEL 5.0 Installatio ... 10:46:40 AM LINUX RESTART ...
    (RedHat)
  • Re: Re: Frequent loss of contact with ISP
    ... >> any unusual error messages. ... > is somewhere in the network config, ... I tried to ping the IP address after the word ... To unsubscribe, ...
    (freebsd-questions)