Do I need these ports open?

Simon Slater pyevet at aapt.net.au
Fri Apr 20 01:13:44 UTC 2007


On Thu, 2007-04-19 at 07:56 +0100, Andy Green wrote:
> Simon Slater wrote:
> > 	Hi all,
> > 
> > 	Just a quick question arising from following another thread.  Here is
> > the result of nmap on a FC6 box:
> > 
> > $ nmap localhost
> This is a misleading test... those ports have something listening on 
> them, that is not the same as being "open" to the outside.  You have 
> done the nmap locally from inside your machine's firewall on the 
> loopback interface, the results will be very different indeed if you 
> instead do the nmap from a second machine on your LAN against your 
> external interface (eg, eth0).
> 
> The only port that should be actually "open" out of the box is the sshd 
> one on 22.
> 
> -Andy
> 
>From another FC6 box on the LAN, the nmap result is the same when
pointing it to the first. Excuse my ignorance, I'm still new to much of
this, shouldn't the samba and nfs ports be also open to others on the
LAN?

Simon




More information about the fedora-list mailing list