How bad to open port 445?

White Widow

Senior member
Jan 27, 2000
773
0
71
Bottom line: I want to be able to access my 2TB Iomega NAS while on travel this week. I have a VPN gateway coming from Newegg, but it won't be here in time. How bad is it to open port 445 on my firewall if it's only forwarded to the NAS and not a full Windows PC? There's nothing on the NAS that's particularly sensitive, and all the folders are password protected.

Thanks,
Aaron
 

reicherb

Platinum Member
Nov 22, 2000
2,122
0
0
If you only forward it to the NAS box, then worst case the NAS box becomes compromised. If the data isn't sensitive, then go for it.
 

Nothinman

Elite Member
Sep 14, 2001
30,672
0
0
And if the NAS becomes compromised it can be used as jumping off point to the rest of the network.

But I would be surprised if your ISP doesn't filter inbound CIFS traffic anyway, I believe most do that these days.
 

Emulex

Diamond Member
Jan 28, 2001
9,759
1
71
BAD. Comcast business has no blocks. use a vpn to bridge services man. it's a linux box. hell use ssl tunneling. anything.
 

Nothinman

Elite Member
Sep 14, 2001
30,672
0
0
BAD. Comcast business has no blocks. use a vpn to bridge services man. it's a linux box. hell use ssl tunneling. anything.

Of course not, business accounts should have no ports blocked. But the OP makes no mention of paying for a business account or the ISP he's using.
 

JackMDS

Elite Member
Super Moderator
Oct 25, 1999
29,487
392
126
As per OP.

Fact 1. I have a VPN gateway coming from Newegg.

Fact 2. There's nothing on the NAS that's particularly sensitive.

Fact 3. All the folders are password protected.

Answer posts.

- - - - - :twisted: - - - :| - :hmm:

I am Not saying that keeping the port open free is good practice, but given the above facts for short period of time ????

.
 

Nothinman

Elite Member
Sep 14, 2001
30,672
0
0
As per OP.

Fact 1. I have a VPN gateway coming from Newegg.

Fact 2. There's nothing on the NAS that's particularly sensitive.

Fact 3. All the folders are password protected.

Answer posts.

- - - - - :twisted: - - - :| - :hmm:

I am Not saying that keeping the port open free is good practice, but given the above facts for short period of time ????

.

Fact 2 doesn't matter, if someone breaks into the NAS they could use that as a jumping off point to anything else on the network or just install something to make it a remotely controlled zombie. Lots of people would rather have your bandwidth more than any of your data.

Fact 3 doesn't mean much either, especially if that password is the same as any oother on the network or some other service like GMail.

Sure he might get lucky and have nothing happen, but it only takes a few minutes to get broken into when you put anything unprotected on the Internet.
 

skyking

Lifer
Nov 21, 2001
22,385
5,355
146
Do you have somebody out of your ISP's network who can do some testing? It would be a shame to think you had it working only to find out otherwise.
IF not:
I would set a strong password for your router and enable remote administration, make sure you had a strong password for your desktop, and set up port forwarding to the desktop but not enable it.
Log in to router, enable port to desktop, log into desktop. Move files as needed.
Turn off port when done.
 

JackMDS

Elite Member
Super Moderator
Oct 25, 1999
29,487
392
126
D
I would set a strong password for your router and enable remote administration, make sure you had a strong password for your desktop, and set up port forwarding to the desktop but not enable it.
Log in to router, enable port to desktop, log into desktop. Move files as needed.
Turn off port when done.

+1

I forgot about this option.

Same can be done for the NAS :thumbsup:

I would also would change the management remote port of the Router to a port of high number (e.g. 63164).


 

Emulex

Diamond Member
Jan 28, 2001
9,759
1
71
if the router is based on FOSS i'd still scan all apps for issued warnings. you know damn well those cheap qnap linux implementations do not get updated with every critical issue (ssh,ftp,apache,etc). so that makes its pretty scarey and a VPN isn't really protection if someone gets in on either side.
 

hawk82

Member
Jul 25, 2004
199
0
76
Why not install hamachi on your Windows 7 PC and then on whatever client computer you are bringing with you? Then you can securely access your NAS (and Win7 computer) without opening any ports to the internet. You'd need to leave your Win7 computer turned on however.
 
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |