Firewall
  1. What is a firewall and what is it used for?
  2. Does Purdue offer a firewall to download?
  3. What firewall ports need to be open for the vpn to work?
What is a firewall and what is it used for?

A firewall is software or hardware that prevents unwanted intrusions onto your system.  A firewall reduces the changes of your computer being compromised by a worm or intruder.

  Print  top Top

Does Purdue offer a firewall to download?

Purdue does not currently license any existing firewall products.  Depending on your platform, however, there are several options that may be available to you.

Windows XP includes ICF (Internet Connection Firewall), which allows you to filter inbound ports. To set up the built-in Internet Connection Firewall (ICF), go to the Start menu, select Settings, then Network Connections, and then your network or dialup connection. Then, select the Advanced options, and turn on the firewall by checking the box, then clicking OK. For detailed instructions, see http://www.purdue.edu/securepurdue/docs/icf.pdf 

Windows 2000 also has some filtering capabilities with its IP Security options found within your Network settings in the Control Panel.

Linux has iptables/ipchains which is a full stateful packet filtering solution.

If you are running on an older Windows platform, or the built-in capabilities are not sufficient, there are also other personal firewall software products, both free and commercial, that you may wish to investigate as well. Try doing a Web search for "personal firewall" to get started.

  Print  top Top

What firewall ports need to be open for the vpn to work?

1.  For IPSec-based VPN (Cisco client among others), you need:  Protocols: 50, 51 (these are not *ports*); and Ports: UDP/500

2.  For PPTP-based VPN, you need:  Protocols: 47; and Ports: UDP/1723

3.  For L2TP, you need: Ports UDP/500 and UDP/1701

Note also that many small office and home office router/firewall appliances such as the Linksys home routers may have a specific option in the configuration to allow VPN connections through the device.  You can consult the vendor documentation for exact instructions on how to configure a particular brand/model.

 

  Print  top Top