CodeConnect.Net Beta


   Explore    Entry   Register  Login  
windowsxp-general
access
windows-vista-mail
windows-vista-general
windowsupdate
windowsmedia-player
access-forms
windows-live-mail-desktop
windowsxp-help_and_support
access-queries
access-modulesdaovba
access-formscoding
windows-server-sbs
windows-server-general
access-reports
windows-vista-music_pictures_video
windowsce-platbuilder
windows-live-messenger
windows-terminal_services
windows-powershell
windows-server-active_directory
access-gettingstarted
windows-mediacenter
windowsxp-hardware
windowsxp-network_web
windows-64bit-general
windows-live-sync
windows-vista-hardware_devices
windows-inetexplorer-ie6_outlookexpress
windows-group_policy
windows-server-networking
windows-vista-installation_setup
windows-vista-networking_sharing
windowsxp-basics
access-tablesdbdesign
windowsxp-perform_maintain
windows-vista-performance_maintenance
windows-networking-wireless
windows-vista-file_management
windows-inetexplorer-ie6-browser
windows-server-dns
windows-server-update_services
windows-vista-security
windows-vista-administration_accounts_passwords
windows-vista-games
windows-file_system
windows-live-foldershare
windows-live-photogallery




Can Reply:  Yes Members Can Edit: No Online: Yes
Zone: > Microsoft News > microsoft.public.windows.vista.security Tags:
Item Type: Date Entered: 11/12/2009 3:37:14 PM Date Modified: Subscribers: 0 Subscribe Alert
Rate It:
NR
XPoints: N/A Replies: 2 Views: 47 Favorited: 0 Favorite
4 Items, 1 Pages 1 |< << Go >> >|
Petr Pisar <pet
NewsGroup User
Return ICMP port unreachable on nonlistening socket11/12/2009 3:37:14 PM
Reply

0

Hello,

common TCP/IP implemetations return ICMP port unreachable error packet
when somobody send packet to port where no server is listening. This was
true even in Windows XP.

However Windows Vista Business SP2 behaves differently. It drops the
packet silently even if given port is allowed for incoming communication
in Advanced firewall settings. (And yes, I'm pretty sure it's really
allowed because in the pfirewall log is not message about dropping.)

I guess this is yet another Windows feature trying to smarter and more
secure than user.

Does anybody know how to get classic behaviour back?

-- Petr
"Mr. Arnold" <A
NewsGroup User
Re: Return ICMP port unreachable on nonlistening socket11/12/2009 4:44:41 PM
Reply

0

Petr Pisar wrote:
> Hello,
>
> common TCP/IP implemetations return ICMP port unreachable error packet
> when somobody send packet to port where no server is listening. This was
> true even in Windows XP.
>
> However Windows Vista Business SP2 behaves differently. It drops the
> packet silently even if given port is allowed for incoming communication
> in Advanced firewall settings. (And yes, I'm pretty sure it's really
> allowed because in the pfirewall log is not message about dropping.)
>
> I guess this is yet another Windows feature trying to smarter and more
> secure than user.


Maybe, IPsec is enabled on the machine with a policy to block ICMP. A
drop message by the FW wouldn't be logged, as IPsec sits in front of the
FW and blocks.

Other than IPsec with an IPsec policy or something else like a 3rd
personal FW solution running on the machine that's doing the blocking,
then nothing else on Vista other than Vista's FW is going to be blocking.

Petr Pisar <pet
NewsGroup User
Re: Return ICMP port unreachable on nonlistening socket11/12/2009 6:51:47 PM
Reply

0

On 2009-11-12, Mr. Arnold <Arnold@Arnold.com> wrote:
> Petr Pisar wrote:
>>
>> common TCP/IP implemetations return ICMP port unreachable error packet
>> when somobody send packet to port where no server is listening. This was
>> true even in Windows XP.
>>
>> However Windows Vista Business SP2 behaves differently. It drops the
>> packet silently
[...]
>
> Maybe, IPsec is enabled on the machine with a policy to block ICMP. A
> drop message by the FW wouldn't be logged, as IPsec sits in front of the
> FW and blocks.
>
> Other than IPsec with an IPsec policy or something else like a 3rd
> personal FW solution running on the machine that's doing the blocking,
> then nothing else on Vista other than Vista's FW is going to be blocking.
>
I have installed the machine and I'm the only administrator of the
system. No third party packet filters nor IPsec policies are installed
or active. FYI, ICMP echo request and replies flow normally.

I found the same complaint on web
(http://www.vistax64.com/vista-security/150480-rejecting-ident-port-113-requests.html), but without solution.

Can anybody at least confirm that it's a bug/feature of Windows Vista?
(I don't have any other system to compare it.)

-- Petr
=?Utf-8?B?T2dM?
NewsGroup User
Re: Return ICMP port unreachable on nonlistening socket11/27/2009 6:55:01 PM
Reply

0

> Can anybody at least confirm that it's a bug/feature of Windows Vista?
> (I don't have any other system to compare it.)

It is a "feature":
http://technet.microsoft.com/en-us/library/dd448557(WS.10).aspx

And I still have not found any way to disable it.

Ondrej
4 Items, 1 Pages 1 |< << Go >> >|







Similar:

denied permission to access folders

windows defender keeps turning itself off - how do i fix this?

registry mechanic....maniac!!

what to make of microsoft security essentials?

still cwindowssystem32mswsockdll,then dial up disconnects and reco

administrator privileges for chkdsk

am i being hacked?

unexpected windows update

power user vs. normal user?

is it possible to decrypt efs files without backup certificate

bitlocker with usb + pin only, without tpm. possible?

uac prompts

can not access shared drive with vpn

security from keyloggers

vista usb monitor is released

windows defender at dial up connection with ie8 on a dell inspiron

error 1606 could not access...

windows defender

lost hope and ideas

41 hosting web www.ivys.es

error code #80072f78 preventing windows update. how can i fix?

enable the .exe security filter

my experience with msse

windows update agent 7.4.7600.226

vista firewall

free security software?

sorry about repost

what is browser defender?

mp scheduled signature update

turning off windows defender real-time

will the shredded files be restored?

win 7 uac group policy equivalents

windows defender efficient ?

questionable file: hpcee.exe

microsoft security essentials group?

microsoft windows search filter host

defender gone from vista

i am still getting disconnected on dial up when the following happ

can't delete file in hidden folder even after changing owner

ie redirects search pages

new user account

avg free software

questionable file: hpcee.exe

kb973636 - error code 52d

question baout vista ultimate firewall

ms security essentials

uac - what does it mean in simple terms?

the security service cannot be started

error code 737d

categorising updates.

   
  Privacy | Contact Us
All Times Are GMT