Packet Filter Policies
56
WatchGuard System Manager
Timbuktu
Timbuktu Pro is remote control and file transfer software used to get access to Windows computers.
The protocol uses TCP port 1417 and UDP port 407. Add the Timbuktu policy and allow access from the
hosts on the Internet that must get access to internal Timbuktu servers, and to the internal Timbuktu
servers.
Timbuktu is not a very secure software application and can put network security at risk. It allows traffic
inside the firewall without authentication. In addition, the Timbuktu server can receive denial-of-
service attacks. We recommend that you use VPN options for more security.
Characteristics
•
Internet Protocol(s): TCP, UDP
•
Port Number(s): TCP 1417, UDP 407
Time
The Time policy is almost the same as NTP. It is used to synchronize clocks between hosts on a network.
Time is usually less accurate and less efficient than NTP across a WAN. We recommend that you use NTP.
Characteristics
•
Internet Protocol(s): TCP, UDP
•
Port Number(s): TCP 37, UDP 37
Traceroute
Traceroute is a software application that creates maps of networks. It is used for network
troubleshooting, network route troubleshooting, and finding the Internet service provider of a site. The
WatchGuard Traceroute policy controls UNIX-based, UDP-style Traceroute only. For a DOS-based or
Windows-based Traceroute packet filter, use the Ping policy. For more information about the Ping
policy, see “Ping” on page 49.
Traceroute uses ICMP and UDP packets to create paths across networks. It uses the UDP TTL field to
send back packets from each router and computer between a source and a destination. If you allow
traceroute to computers protected by your Firebox®, this can enable a hacker to create a map of your
private network.
Characteristics
•
Internet Protocol(s): UDP
•
Port Number(s): 33401-65535
UDP
This policy serves as the default policy for all UDP connections, and other policies override it. UDP
connections that do not match specified policies in Policy Manager do not complete unless UDP, TCP-
UDP, or the TCP Proxy are also configured in Policy Manager.
•
Internet Protocol(s): UDP
•
Port Number(s): 0 (Any)