Home > Ask the Security Experts > Network Security Questions & Answers > Can open ports increase LAN exposure?
Ask The Security Expert: Questions & Answers
EMAIL THIS

Can open ports increase LAN exposure?

Mike Chapple EXPERT RESPONSE FROM: Mike Chapple

Pose a Question
Other Security Categories
Meet all Security Experts
Become an Expert for this site


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


>
QUESTION POSED ON: 03 September 2006
I have a Router on my LAN that connects all host PCs to each other. My router has an open port for Internet access, (and there will be an open port for my future remote desktop terminal connections). How exposed is my LAN? Can a port scanner see my router and its open port? Or is it only hosts whom I connect to that can become aware of my IP Address?

>
EXPERT RESPONSE
In general, you should not have any open ports on the front of your router/firewall unless you're hosting a service (e.g. a Web site) on your local network that requires public access. Most small/home office routers come with a default policy that is configured to allow any outbound traffic and deny all inbound traffic. This is the desired policy, and I'd strongly recommend that you stick with it.

You mentioned a future requirement for remote desktop connections. If you do expose a remote management port, you should ensure that it's using a strongly encrypted connection or is tunneled through a virtual private network (VPN). If at all possible, you should also limit access to specific IP addresses, ones from which you expect inbound connections.


Sound Off! -   Be the first to post a message to Sound Off!


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


RELATED CONTENT
Network Security
Will Cisco's plan to open access to the IOS improve network security?
Will VoIP attacks result in more than just spam?
Should enterprises implement a mandatory iPhone VPN?
Will organizations that lag behind on IPv6 adoption have greater security risks?
Should iPhone email be sent without SSL encryption?
How to secure an FTP connection
DMVPN configuration: Is an additional firewall needed between the router and the Internet?
Is centralized logging worth all the effort?
What are the pros and cons of shaping P2P packets?
Should an ISP keep corrupted machines off of a network?

IPSec
Is an IPsec VPN necessary when connecting remote servers that process financial transactions?
What ports should be opened and closed when IPsec filters are implemented?
DMVPN configuration: Is an additional firewall needed between the router and the Internet?
How should the ipseccmd.exe tool be used in Windows Vista?
Can Trojans and other malware exploit split-tunnel VPNs to infiltrate a network?
IPsec tunneling: Exploring the security risks
Should an IT staff be concerned with a network's physical security?
How expensive are IPsec VPN setup costs?
Do split-tunneling features make a VPN vulnerable?
Will securing a wireless LAN make the data link layer vulnerable?
IPSec Research

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
Internet Key Exchange  (SearchSecurity.com)
IPsec  (SearchSecurity.com)
network encryption  (SearchSecurity.com)
virtual private network  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



Search and Browse the Expert Answer Center
Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
Browse our Expert Advice

TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineWebcastsWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




All Rights Reserved, Copyright 2003 - 2008, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts