How can I allow an application on default and a non-standard port?

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

How can I allow an application on default and a non-standard port?

L1 Bithead

I have a Security rule that allows Oracle traffic between two subnets.  The problem is that three Oracle servers use standard port 1521, and another Oracle Server uses a non-standard port 13062.  I know that I need to allow the non-standard port in the rule, but that breaks traffic on the standard port.  For now, I have explicitly added the standard port, so both ports are explicitly allowed.

 

Is there a way to allow application-default + defined services in a single rule?

 

Thanks

1 accepted solution

Accepted Solutions

Cyber Elite
Cyber Elite

@kcampion,

Your only option for this is either the way you are doing it currently where you manually specify the default ports as a service/member along with your custom ports, or to split the entry into two separate rulebase entires. I know there's an FR to allow exactly what you are asking for, but I can't recall what it was off-hand. 

View solution in original post

4 REPLIES 4

L1 Bithead

By the way, I have the same problem with ping.  As soon as I define the non-standard port, ping breaks, and I haven't found ay way to explicitly include a "service" for ping in the same rule.

Cyber Elite
Cyber Elite

@kcampion,

Your only option for this is either the way you are doing it currently where you manually specify the default ports as a service/member along with your custom ports, or to split the entry into two separate rulebase entires. I know there's an FR to allow exactly what you are asking for, but I can't recall what it was off-hand. 

@kcampion,

As for ping that's ICMP traffic and doesn't really fit the same model and you should never really have non-standard ping traffic. 

Thanks @BPry , I thought that was the case for mixing standard and non-standard ports.

 

Thanks for the reply on the ping issue too.  I'm not trying to allow ping on non-standard, but I can't find a way to get the standard method for ping to work when mixed my non-standard Oracle.  Not a big deal, I'm OK with splitting the ping from the Oracle rule.

  • 1 accepted solution
  • 4457 Views
  • 4 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!