Microsoft RPC (MSRPC) support

All,

I have a Windows Server inside my firewall which service must be reached via Microsoft-style RPC (MSRPC) by customers who are outside. How to set the proper firewall? (In which case it is important, the code is FWSM Firewall Version 2.3 (1).)

If I understand correctly, MSRPC works as follows. (Please alert me on mistakes.) The customer wants to use a service that provides the server, but the service was not a well known port number. Instead, the service is identified by a famous 'programme number.' The customer contacts 135/tcp port on the server, specifies the number of program of your choice and says on what port number of the service is listening. The customer then proceeds to contact service in the usual way (fee connection; full negotiating TCP) on the port, that he learned to use.

This behavior is a problem. The firewall must allow second connection of the client, but the port of destination may not be known (or so configured in the firewall) in advance. In support of MSRPC, therefore, I expect the firewall to have a correction. There no one for MSRPC, if it is of * seem * to have a non configurable for Sun RPC style. (See PIX Firewall & VPN Config Guide p. 5-29) It is supposed to be a SunRPC correction, example of the documentation implies that you just need to identify the service port forward using "rpcinfo" on the client, and then configure the firewall in a static way. Is it really a good idea? It is possible for the service to use a different port at different times, correct? And how is what is considered fixup? (What correction happening?)

In any case, documentation mentions MSRPC again in the Appendix devoted to support MS Exhange and suggests the use of the command 'established '. Documentation for this command, however, said that it "allows outbound connections back through the PIX firewall access.» In my case, I am concerned by the incoming connections.

Thanks a lot for any advice you can offer.

Christopher Ursich

I'm not a PIX / IOS fix up for this. But it's how Microsoft is going to solve this problem:

http://msdn.Microsoft.com/library/default.asp?url=/library/en-us/dndcom/html/msdn_dcomfirewall.asp

< very="" brief="" summary="" of="" the="" above="" document="">>

Restrict the range of TCP Ports

There are several registry settings that control the functionality of DCOM ports restriction. All of the below named values are located under the key HKEY_LOCAL_MACHINE\Software\Microsoft\Rpc\Internet registry (that you must create). Remember, just do it on the server machine. Customers will automatically get port numbers right when they connect to the MCU on the server machine.

Name ports

Type REG_MULTI_SZ.

Value of 3000-4000 (specify a port range per line. One or more ranges of ports. )

Your firewall configuration

The firewall between your server and the Internet must be configured as follows:

Refuse all incoming traffic from the Internet to your server.

Allow incoming traffic to all customers for the TCP 135 port (and the port UDP 135, if necessary) on your server.

Allow incoming traffic from all the clients to TCP ports (UDP ports and, if necessary) on your server in the range of Ports (s) indicated above.

Volker greetings

Tags: Cisco Security

Similar Questions

  • Microsoft does not support my printer Canon MX-340. / Why not.

    I get a dialog box indicating that Microsoft doesn't support my Canon MX-340. (Microsoft does not support my printer Canon MX - 340 / why not.)

    I would be very surprised if it was what the error actually says.

    It's the cannon to provide a driver for activate windows control a printer.  Visit the Canon Website and download the driver appropriate for your printer and operating system - something you haven't actually told us.

  • Microsoft Visual FoxPro support library

    I did a system restore on my computer running windows XP and now I get a message when I try and open some software "cannot find Microsoft Visual FoxPro Support Library".  Can someone direct me to a solution

    THX

    I did a system restore on my computer running windows XP and now I get a message when I try and open some software "cannot find Microsoft Visual FoxPro Support Library".  Can someone direct me to a solution

    THX

    As this is the forum for Windows Update, suggest you post this or wait for a moderator move this question to the general Visual FoxPro forum .
    Thanks for your patience, jandknite! MowGreen Services update - consumer safety

  • Microsoft has a support center India/Asia calling houses UK?

    Microsoft has a support center India/Asia calling houses UK? or is that what I think a scam.

    In the United Kingdom is flooded with calls from other countries with callers using English names to try to scam people. FACT!
    Microsoft is normally contact people by phone? If I remember never submit my Microsoft phone number.

    It is a common scam. Do not let them give any info, do not give access to your PC, not give them all the money and do not go to all the websites that they suggest. One moment. See:

    http://www.microsoft.com/en-gb/security/online-privacy/msname.aspx .

    Microsoft does ever not requested for calls.

    (such persons may use names other than Microsoft as well)

  • Network adapter (device Bluetooth (Personal Area Network) and Btooth works does not after installing W 7 Ultimate__ (Situation Reported to microsoft Hel and Support under SRX1120597135ID Without solution untill today))

    BTooth works do not after Windows Vista upgrade (Btooth works without problems) for W7
    At the moment I have problems connection BlackBerry device and other devices via Btooth
    messages 1: 'softwarfe device driver was not successfully installed ".
    message 2: "WIDDCOMM Bluetooth Software 6.1.04403 Dell Incompatible" (WIDCOMM = Broadband - manufacturer)
    In short, the list obtained messages:
    1 device driver software was not compatible
    2. incompatible software Bluetooth
    3. the drivers are not installed: lists of codes (31) (28) (10)

    Report of the final situation for Microsoft Help and Support under SRX1120597135ID (withoutany positive response so far, I have been asked to report through this forum, I hope a solution will be here)
    I tried all the options you will find in google without success.

    I contacted Dell and Bradband and I have upgraded to WIDCOMM Bluetooth Software 6.2.0.6600 available in Dell Support without positive results.

    Repost: Windows Update has nothing to do with the upgrade of Windows. Posting here instead: http://social.answers.microsoft.com/Forums/en-US/w7hardware/threads ~ Robear Dyer (PA Bear) ~ MS MVP (that is to say, mail, security, Windows & Update Services) since 2002 ~ WARNING: MS MVPs represent or work for Microsoft

  • I use Windows XP and care April 2014 if I always use the it, what will happen after that Microsoft no longer supports it?

    I use Windows XP and care April 2014 if I always use the it, what will happen after that Microsoft no longer supports it?  My computer will become unusable?  It works great and I would keep it if I can.  I use a Dell Inspiron 530 desktop.  Some people have told me that "nothing will happen" and others tell me that my computer will be more vulnerable.  I use ESET NOD 32 and Malwarebytes.  They tell me that they should still continue to work.  I am told that because my computer was purchased in September 2008, he cannot me upgraded to Windows 7.  I'm not a geek and would need assistance "passage" my files from one computer to the other as well.  And then what to do with my old top office.  I'm very worried and I had to face the fact that Microsoft is not going to deliver any security updates patches after April of 2014.

    I can't wait to hear from someone on this problem and more just to go out and invest in Windows 8!  Thank you.

    I can tell you one thing, all or almost of windows xp device drivers will disappear from the computer manufacturers support websites and will reappear on all these shady sites who claim to be download for free but comes with unwanted software. Download the latest device drivers and keep several copies of them and download them to your skydrive or dropbox account fo guard.

    I doubt that will happen. I've seen Windows 2000 drivers still on websites mfg.

  • Microsoft always does support Vista?

    Microsoft always does support Vista?

    Also, I get a message to update my Vista drivers.  I tried to see if that is in fact coming from Microsoft before I say go ahead and update.

    Thank you!

    Next time you have a computer problem, please start you own Thread/question instead of add to someone else's problems.

    Driver downloads:

     

    Acer:

    http://us.Acer.com/AC/en/us/content/drivers

     

    ADVENT:

    http://www.adventcomputers.co.UK/product-downloads

     

    Alienware:

    http://support.Alienware.com/Support_Pages/Restricted_Pages/driver_downloads.aspx

     

    ASUS:

    http://www.ASUS.com/support

     

    Dell:

    http://www.Dell.com/support/drivers/us/en/19/ProductSelector

    eMachines:

    http://www.eMachines.com/EC/en/us/content/drivers

    Fujitsu:

    http://www.Fujitsu.com/us/support/

    Gateway:

    http://us.gateway.com/GW/en/us/content/drivers-downloads

    HP:

    http://WWW8.HP.com/us/en/drivers.html

    Lenovo:

    http://support.Lenovo.com/en_US/downloads/default.page#

    LG:

    http://www.LG.com/us/support/software-manuals

    Samsung:

    http://www.Samsung.com/us/support/downloads

    Sony Vaio:

    http://eSupport.Sony.com/Perl/select-System.pl?Director=driver

    Toshiba:

    http://support.Toshiba.com/drivers

  • Microsoft has no support for windows 7?

    Microsoft has no support for windows 7?

    If your operating system is preinstalled on your computer, your support should be provided by the manufacturer (OEM) who provided the computer rather than Microsoft.  Microsoft will provide free assistance for problems of installation of Service Packs and updates for Windows even if your machine is an OEM.

    Start a new post in this Forum and include details of any problems you encounter and the people here will do their best to help you find a solution.

    How to ask a question
    http://support.Microsoft.com/default.aspx/KB/555375

    Microsoft Technical Support phone numbers
    http://support.Microsoft.com/kb/319726/en-us

    Microsoft U.S. Office locations
    http://www.Microsoft.com/about/companyinformation/usaoffices/en/us/default.aspx

    Online Assisted Support options
    http://support.Microsoft.com/select/default.aspx?target=assistance

    Microsoft contact information - Is supported by the phone number, Email
    http://support.Microsoft.com/GP/phonelist#phone

    Contact Microsoft
    http://support.Microsoft.com/contactus/?ws=mscom#TAB0

  • I use Windows XP Professional. I heard that Microsoft will withdraw support for XP on July 13, 2010. But my software is stll update. Why?

    I thought that Microsoft stop updaing the software fom July 13, 2010. Now, think of Microsoft updates the part of the security of this software. Is it so?  The main problem is that updates are occupaying space of a part of 'C' for my computer very quickly. How to handle the problem?

    Windows XP SP2 support ends July 13, 2010. Extended support for WinXPSP3 will continue through April 8, 2014.

    In re your problem of disk space, see this discussion: http://aumha.net/viewtopic.php?f=62&t=33827

    ~ Robear Dyer (PA Bear) ~ MS MVP (that is to say, mail, security, Windows & Update Services) since 2002 ~ WARNING: MS MVPs represent or work for Microsoft

  • Microsoft Help and support

    Hello using microsoft and family motor mount on my windows vista premium does not show images, photos, or arrows, it display only TEXT! and photos or other images were shown as small red cross or just a small box empty. It happened when I connect to the first online help, but after I try the online and offline help in the settings part, but does not work!
    Need help please.

    Windows Vista Help and Support pages are not displayed properly (MVP Ramesh) - http://www.winhelponline.com/articles/194/1/ MS - MVP - Elephant Boy computers - Don ' t Panic!

  • Microsoft Windows Tech Support - fake phone call or not?

    I got a phone call from someone who wanted typing me eventvwr and watch errors and warning signs - I did.  I noticed that they were that all dated the previous day or just before the phone call.  I was asked to have malicious bugs deleted by this PROVIDER of SUPPORT of MICROSOFT WINDOWS TECHINICAL for £79.  The person says his name is Michael and his phone was quoted as 02034117907.

    My virus package pick up any info - however, errorfix now has up to 3,000 privacy, whenever I use it's about 4 times a day.

    Help please - does anyone know if the call was authentic or not and any ideas on the reasons of privacy now is off the scale!

    Thank you

    FAKE!

    CF. http://social.answers.microsoft.com/Forums/en-US/msescan/thread/28388b37-9a69-419d-9e45-6ab45f611693

    ~ Robear Dyer (PA Bear) ~ MS MVP (that is to say, mail, security, Windows & Update Services) since 2002 ~ WARNING: MS MVPs represent or work for Microsoft

  • Microsoft Help and support has stopped working (Vista)

    Well basically I get the screen of Windows security alerts reminder (would like to disable the account of the user control to pass his remarks).  So I thought, what the hell I'll click the blue how to help my computer control user account.  So that's what I get and I'm scratching my head to make it go away! Suggestions:

    Signature of the problem:

    Problem event name: APPCRASH

    Application name: helppane.exe

    Application version: 6.0.6001.18000

    Application timestamp: 4791945e

    Fault Module name: apss.dll

    Fault Module Version: 6.0.6001.18000

    Timestamp of Module error: 4791a 630

    Exception code: c0000005

    Exception offset: 0001ca6b

    The system version: 6.0.6002.2.2.0.768.3

    Locale ID: 1033

    Additional information 1: fd00

    More information 2: ea6f5fe8924aaa756324d57f87834160

    Additional information 3: fd00

    Additional information 4: ea6f5fe8924aaa756324d57f87834160

    Read our privacy statement:

     

    Hi Msalice,

    Welcome to the Windows Vista answers Forum!

    I have a few questions about your question:

    (a) when exactly you receive the error?

    (b) how long have you encountered the problem?

    (c) have you installed the Windows updates or software installed

    You can try to disable user account control. Follow the below given steps:

    1. open user accounts by clicking the Start button, click Control Panel, click user accounts and family safety (or by clicking on user accounts, if you are connected to a network domain), and then clicking user accounts.

    2. click on turn on UAC enabled or disabled. If you are prompted for an administrator password or a confirmation, type the password or provide confirmation.

    3. Select the check box to turn on UAC, or clear the checkbox to disable UAC use User Account Control (UAC) to help protect your computer , and then click OK.

    For more information, please visit the below given link:

    Enable or disable the User Account Control

    http://Windows.Microsoft.com/en-us/Windows-Vista/turn-user-account-control-on-or-off

    You can also try a system restore to set the system to a point where it was working fine.

    To restore the operating system to an earlier point in time, follow these steps:

    1. Click Start, type system restore in the search box, and then click System Restore in the list programs.

    If you are prompted for an administrator password or a confirmation, type your password or click on continue.

    2. in the System Restore dialog box, click on choose a different restore point and then click Next

    3. in the list of restore points, click a restore point created before you started having the problem, and then click Next

    4. click on finish

    Note: When you perform the system restore to restore the computer to a previous state, programs and updates that you have installed are removed.

    For more information, please follow the below given link:

    How to repair the operating system and how to restore the configuration of the operating system to an earlier point in time in Windows Vista

    http://support.Microsoft.com/kb/936212/

    Hope this information is useful.

    Amrita M

    Microsoft Answers Support Engineer
    Visit our Microsoft answers feedback Forum and let us know what you think.

  • Microsoft asked "Etechnical support" people to phone directly to a problem with their computers?

    Somone called 'Mike' called "E-technical support" (I think that's what he said). He said that Microsoft had reported a problem with my Windows software and that he had been asked to solve the problem. Who is the 'E - technical Support'?  Microsoft makes no reference to issues of client computer to another body of support?

    John D B

    Sounds like a scam, ignore him.

  • Why microsoft used to support fsx insisting on a product code when all I have is the product key that has been authorized for bu activation does not match their input format

    trying to get a simple answer to my question, I asked the support of microsoft for the contact to ask someone who knows about flight simulator but I can't spend the screen requests I have enter product code - I walked into the box of the product id provided key interest which enabled but said stupid site simply enter the code in the indicated format and it does not match this format once again , I can't communicate with them-i suspect that it is a ploy because there is no available support and it's a time of great runaround.last they do not recognize my computer id code - this time, they have recognized my computer but then obscured code fsx - i don't believe that someone will read this-i has recently received a message to say that my thread on an unanswered question them earlier had been removed and I was wondering who decides that - always has to be someone in life at microsoft

    Hello

    Where have you bought Microsoft Flight Simulator X for?

    Follow the steps in this article.


    Solving the problems of activation for Microsoft games and mapping programs

    http://support.Microsoft.com/kb/960480

    Also see this article:

    How to get a new product key for Microsoft Games for Windows, Streets & Trips, or MapPoint
    http://support.Microsoft.com/kb/973457

    If the problem persists, Flight Simulator supports for assistance.
    http://www.Microsoft.com/products/games/FSInsider/tips/pages/default.aspx

    Kind regards
    Afzal Taher
    Microsoft technical support engineer

  • Microsoft does not support this problem?

    It seems that, on computers across the world, vista Photo Gallery has suddenly stopped working. All my pictures are .jpg and have all been working fine on the same vista laptop for the past 2 years. He had no problem with them on Friday, March 5, 2010. Sunday, March 14 I started to get the same error message as everyone else - "unable to open the Photo Gallery of the photo or video. The file format is not supported or you do not have the latest updates." Neither of these two things is true, what happens? If I open the pictures with another program, they are all very well, so certainly a Windows problem.

    I filed a request for help from Microsoft, which has not been answered. Anyone know what is happening?

    Hi Diana,

    Thanks for your reply. I had already tried your suggestions because they were among the few that I had managed to find in your forums. They do not work for me. All my photos are saved on memory sticks, and all are not corrupt and can be seen by every viewer of photos on my computer except the windows photo gallery. So I guess that the problem has to be there.

    I find library useful for creating slide shows and a few other things so I'd like to solve this problem. The forums are not very useful - a lot of people with this problem, but not a lot of Microsoft solutions. Do you have any other ideas? Can photo library have lost some vital pieces somehow? If so, how can I fix without doing a complete reinstall of Vista Business?

Maybe you are looking for

  • Error using NI9268

    Hello I try to use NI9268 CAN module for the first time (with a CRIO 9081). When I connect it I can get it to the MAX but I got the following error after the self-test: 0xBFF63001 (screenshot 1). Then, when I want to start the bus interface, I have e

  • Error 800b0100 code after trying to install KB2416470

    I tried to install this update of security for some time now. I tried to install the analysis TOOL and I still have this problem. Also, I rebooted the computer and tried to cut the firewall so to download. Always down. Whats up with that? I guess I'l

  • Create a repair of emergency CD bootable for XP disc?

    Is it possible to create a disc of CD bootable for XP emergency repair? The question is vs CD disks 1. create a bootable CD from a pc can be used with the XP operating system? and/or 2. create a bootable from a floppy CD? (emergency repair disk)? As

  • Someone knows how to upgrade to Windows 7 64 bit to dm3?

    Hi all Recently, I bought my computer laptop pavilion dm3-1028tx (sp9300, 4 GB ddr3). Unfortunely only it comes with oem windows 7 Home premium 32-bit instead of windows 7 64-bit. Due to the characteristic of 32 bits, its only 3 GB of ram could be us

  • is a registry cleaner program a good investment for a slow computer?

    Hello. My computer is slow and late, most of the time when I go on facebook the freez the computer for 10-15 seconds, then the page comes on. The more problems I have on facebook is when I go to the games (the game will load completely and before it