<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PlusNet Firewall - Port Blocking Suggestions in Plusnet Feedback</title>
    <link>https://community.plus.net/t5/Plusnet-Feedback/PlusNet-Firewall-Port-Blocking-Suggestions/m-p/988714#M40734</link>
    <description>Well it's still the case. I changed product recently and read through the list of "closed questions" that are generated (8 on total) on &lt;A href="https://www.plus.net/wizard/?p=search" target="_blank"&gt; Help Assistant - Your Questions&lt;/A&gt;&lt;BR /&gt;Service Notification&lt;BR /&gt;1:49am, Saturday 11 May 2013&lt;BR /&gt;The customer\'s firewall settings have been updated to \"Firewall off\"&lt;BR /&gt;The generated email should direct the customer to check the "closed questions" to make sure everything is OK.&lt;BR /&gt;(The Plusnet internal ticket is/was #74543)&lt;BR /&gt;&lt;BR /&gt;</description>
    <pubDate>Mon, 13 May 2013 16:10:18 GMT</pubDate>
    <dc:creator>MsDizzie</dc:creator>
    <dc:date>2013-05-13T16:10:18Z</dc:date>
    <item>
      <title>PlusNet Firewall - Port Blocking Suggestions</title>
      <link>https://community.plus.net/t5/Plusnet-Feedback/PlusNet-Firewall-Port-Blocking-Suggestions/m-p/988711#M40731</link>
      <description>Dear Plus Net Admin Guru's,&lt;BR /&gt;Firstly, thank you for providing a set of Server side firewall settings which can be chosen and set up by the user &lt;img class="lia-deferred-image lia-image-emoji" src="https://community.plus.net/html/@104CD63F9302A50EF5EC70FE32BB8AA1/images/emoticons/smiley.gif" alt="Smiley" title="Smiley" /&gt; and I have some suggestions to improve the service...&lt;BR /&gt;1. Add uPnP to the list of ports blocked in both the "low" and "High" protocol settings.&amp;nbsp; These ports, as you will be aware, are for use inside a network only and should never be open on the public facing side of the network.&amp;nbsp; However, a recent exploit (set out in great detail on the Security Now Podcast - Episode 389 &lt;A href="http://twit.tv/show/security-now/389"&gt;http://twit.tv/show/security-now/389&lt;/A&gt; and by Rapid 7 in their report (NB: Download link) &lt;A href="http://bit.ly/upnpflaws"&gt;http://bit.ly/upnpflaws&lt;/A&gt;) detail that worldwide there are some 81 million routers which open uPnP to the "public" facing side of the internet and therefore allow the network to be attacked remotly by some unscrupulous individuals.&lt;BR /&gt;If PlusNet blocked UDP port 1900 and TCP port 2869 in both the "low" and "High" protocol settings this would prevent any attack on a vulnerable Plus Net user without any issues to the users connection... these ports should not be functional on the public facing side in any event!!&lt;BR /&gt;Rapid 7's recommendations to ISP's in light of this exploit was:&lt;BR /&gt;&lt;BLOCKQUOTE&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;Quote&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;B&gt;Internet Service Providers&lt;/B&gt;&lt;BR /&gt;ISPs should review any equipment that they are providing to subscribers to verify that UPnP is not exposed on the WAN interface.&lt;BR /&gt;If the equipment is affected, one of the following solutions should be considered:&lt;P&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Pushing a configuration update that disables UPnP across the subscriber base&lt;/LI&gt;&lt;BR /&gt;&lt;LI&gt;Pushing a software update that removes UPnP capabilities from the device&lt;/LI&gt;&lt;BR /&gt;&lt;LI&gt;Replacing customer equipment with a device that can be configured securely&lt;/LI&gt;&lt;BR /&gt;&lt;LI&gt;Implementing network-wide ACLs for UDP port 1900 and specific TCP ports&lt;/LI&gt;&lt;BR /&gt;&lt;/UL&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/BLOCKQUOTE&gt;&lt;BR /&gt;Implementing the network wide block on uPnP seems like a sensible and quick way of protecting Plus Net users from this exploit.&lt;BR /&gt;2. Turn on the firewall to low by default for all subscribers and e-mail them all to suggest that High may be a more appropriate setting for them.&lt;BR /&gt;Many thanks&lt;BR /&gt;Andy</description>
      <pubDate>Thu, 11 Apr 2013 09:23:27 GMT</pubDate>
      <guid>https://community.plus.net/t5/Plusnet-Feedback/PlusNet-Firewall-Port-Blocking-Suggestions/m-p/988711#M40731</guid>
      <dc:creator>andyleemeuk</dc:creator>
      <dc:date>2013-04-11T09:23:27Z</dc:date>
    </item>
    <item>
      <title>Re: PlusNet Firewall - Port Blocking Suggestions</title>
      <link>https://community.plus.net/t5/Plusnet-Feedback/PlusNet-Firewall-Port-Blocking-Suggestions/m-p/988712#M40732</link>
      <description>I don't think much of our chances getting this suggestion implemented. Four years ago it was discovered that the firewall was turned off each time one changed product. In February 2013 I discovered that this was still the case.&lt;BR /&gt;&lt;A href="http://community.plus.net/forum/index.php/topic,74679.0.html" target="_blank"&gt;http://community.plus.net/forum/index.php/topic,74679.0.html&lt;/A&gt;</description>
      <pubDate>Thu, 11 Apr 2013 09:58:57 GMT</pubDate>
      <guid>https://community.plus.net/t5/Plusnet-Feedback/PlusNet-Firewall-Port-Blocking-Suggestions/m-p/988712#M40732</guid>
      <dc:creator>alanf</dc:creator>
      <dc:date>2013-04-11T09:58:57Z</dc:date>
    </item>
    <item>
      <title>Re: PlusNet Firewall - Port Blocking Suggestions</title>
      <link>https://community.plus.net/t5/Plusnet-Feedback/PlusNet-Firewall-Port-Blocking-Suggestions/m-p/988713#M40733</link>
      <description>Thanks for the feedback and the suggestion about that.</description>
      <pubDate>Thu, 11 Apr 2013 11:09:09 GMT</pubDate>
      <guid>https://community.plus.net/t5/Plusnet-Feedback/PlusNet-Firewall-Port-Blocking-Suggestions/m-p/988713#M40733</guid>
      <dc:creator>adamwalker</dc:creator>
      <dc:date>2013-04-11T11:09:09Z</dc:date>
    </item>
    <item>
      <title>Re: PlusNet Firewall - Port Blocking Suggestions</title>
      <link>https://community.plus.net/t5/Plusnet-Feedback/PlusNet-Firewall-Port-Blocking-Suggestions/m-p/988714#M40734</link>
      <description>Well it's still the case. I changed product recently and read through the list of "closed questions" that are generated (8 on total) on &lt;A href="https://www.plus.net/wizard/?p=search" target="_blank"&gt; Help Assistant - Your Questions&lt;/A&gt;&lt;BR /&gt;Service Notification&lt;BR /&gt;1:49am, Saturday 11 May 2013&lt;BR /&gt;The customer\'s firewall settings have been updated to \"Firewall off\"&lt;BR /&gt;The generated email should direct the customer to check the "closed questions" to make sure everything is OK.&lt;BR /&gt;(The Plusnet internal ticket is/was #74543)&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Mon, 13 May 2013 16:10:18 GMT</pubDate>
      <guid>https://community.plus.net/t5/Plusnet-Feedback/PlusNet-Firewall-Port-Blocking-Suggestions/m-p/988714#M40734</guid>
      <dc:creator>MsDizzie</dc:creator>
      <dc:date>2013-05-13T16:10:18Z</dc:date>
    </item>
    <item>
      <title>Re: PlusNet Firewall - Port Blocking Suggestions</title>
      <link>https://community.plus.net/t5/Plusnet-Feedback/PlusNet-Firewall-Port-Blocking-Suggestions/m-p/988715#M40735</link>
      <description>Well &lt;A href="http://community.plus.net/forum/index.php/topic,74679.msg989973.html#msg989973" target="_blank"&gt;I've asked for an update&lt;/A&gt; on the issue of the Firewall being off on New/Change of Product.</description>
      <pubDate>Tue, 14 May 2013 17:55:44 GMT</pubDate>
      <guid>https://community.plus.net/t5/Plusnet-Feedback/PlusNet-Firewall-Port-Blocking-Suggestions/m-p/988715#M40735</guid>
      <dc:creator>Anotherone</dc:creator>
      <dc:date>2013-05-14T17:55:44Z</dc:date>
    </item>
    <item>
      <title>Re: PlusNet Firewall - Port Blocking Suggestions</title>
      <link>https://community.plus.net/t5/Plusnet-Feedback/PlusNet-Firewall-Port-Blocking-Suggestions/m-p/988716#M40736</link>
      <description>What I would like to see is a setting to truly block P2P traffic.&lt;BR /&gt;Can't not be done successfully with a simple port filter it needs something much more sophisticated. But Plusnet must have the necessary technology as they can traffic manage P2P traffic.&lt;BR /&gt;The reason I suggest this is I see lots of posts (in other forums) asking how to stop someone on the home network from using P2P, hogging the bandwidth, and disrupting everyone else's internet. It's often from someone in student accommodation &lt;img class="lia-deferred-image lia-image-emoji" src="https://community.plus.net/html/@0FA1396AC0773F33E2DC472BB4F75D3C/images/emoticons/wink.gif" alt="Wink" title="Wink" /&gt;&lt;BR /&gt;I'm sure such a system would be a good marketing point for the ISP.&lt;BR /&gt;eg stop one person hogging the bandwidth, downloading questionable material and leaving the owner responsible etc.</description>
      <pubDate>Tue, 14 May 2013 22:35:47 GMT</pubDate>
      <guid>https://community.plus.net/t5/Plusnet-Feedback/PlusNet-Firewall-Port-Blocking-Suggestions/m-p/988716#M40736</guid>
      <dc:creator>npr</dc:creator>
      <dc:date>2013-05-14T22:35:47Z</dc:date>
    </item>
    <item>
      <title>Re: PlusNet Firewall - Port Blocking Suggestions</title>
      <link>https://community.plus.net/t5/Plusnet-Feedback/PlusNet-Firewall-Port-Blocking-Suggestions/m-p/988717#M40737</link>
      <description>Isn't that what the &lt;A href="https://portal.plus.net/surf/" target="_blank"&gt;"Safe Surf Option"&lt;/A&gt; is supposed to do ?</description>
      <pubDate>Tue, 14 May 2013 22:45:37 GMT</pubDate>
      <guid>https://community.plus.net/t5/Plusnet-Feedback/PlusNet-Firewall-Port-Blocking-Suggestions/m-p/988717#M40737</guid>
      <dc:creator>Anonymous</dc:creator>
      <dc:date>2013-05-14T22:45:37Z</dc:date>
    </item>
    <item>
      <title>Re: PlusNet Firewall - Port Blocking Suggestions</title>
      <link>https://community.plus.net/t5/Plusnet-Feedback/PlusNet-Firewall-Port-Blocking-Suggestions/m-p/988718#M40738</link>
      <description>It's supposed to, but as has been pointed out before, you can configure your own ports in some P2P software. Whilst Safe Surf might stop the basic stuff and perhaps average youngsters from doing P2P, the clever buggers will soon find ways round it and tell their less clever mates. So, I quite like npr's idea, but I think it ought to be part of a modified Safe Surf rather than the Firewall.&lt;BR /&gt;What I would like to see with the Firewall would be a sort of Super High setting which blocks all incoming ports to all protocols but allows the user to configure which ports and protocols to open.&lt;BR /&gt;</description>
      <pubDate>Tue, 14 May 2013 23:18:27 GMT</pubDate>
      <guid>https://community.plus.net/t5/Plusnet-Feedback/PlusNet-Firewall-Port-Blocking-Suggestions/m-p/988718#M40738</guid>
      <dc:creator>Anotherone</dc:creator>
      <dc:date>2013-05-14T23:18:27Z</dc:date>
    </item>
    <item>
      <title>Re: PlusNet Firewall - Port Blocking Suggestions</title>
      <link>https://community.plus.net/t5/Plusnet-Feedback/PlusNet-Firewall-Port-Blocking-Suggestions/m-p/988719#M40739</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;Quote from: Anotherone&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Well &lt;A href="http://community.plus.net/forum/index.php/topic,74679.msg989973.html#msg989973" target="_blank"&gt;I've asked for an update&lt;/A&gt; on the issue of the Firewall being off on New/Change of Product.&lt;BR /&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/BLOCKQUOTE&gt;&lt;BR /&gt;So you have Anotherone and I missed it!. Anyway, I was just trying to highlight that we would like a response from Plusnet to see what's happening on this particular issue that's been outstanding for a few &lt;B&gt;years!!!&lt;/B&gt;&lt;BR /&gt;I assumed Safe Surf was targeted at families, but I can see that bandwidth hogs etc in a household can cause a few problems too.</description>
      <pubDate>Tue, 14 May 2013 23:36:12 GMT</pubDate>
      <guid>https://community.plus.net/t5/Plusnet-Feedback/PlusNet-Firewall-Port-Blocking-Suggestions/m-p/988719#M40739</guid>
      <dc:creator>MsDizzie</dc:creator>
      <dc:date>2013-05-14T23:36:12Z</dc:date>
    </item>
    <item>
      <title>Re: PlusNet Firewall - Port Blocking Suggestions</title>
      <link>https://community.plus.net/t5/Plusnet-Feedback/PlusNet-Firewall-Port-Blocking-Suggestions/m-p/988720#M40740</link>
      <description>@purleigh,&lt;BR /&gt;Thanks I wasn't aware of PN's safe surf, only been here a few months.&lt;BR /&gt;I've now had a look and am sorry to say I find it a tad under whelming. IMO it's too basic to block most P2P software, in fact it will not even block my own usenet connection.&lt;BR /&gt;Sorry for the rant, but I feel strongly about security software which promises what it's can't deliver is just another form of malware IMO.&amp;nbsp;  &lt;img class="lia-deferred-image lia-image-emoji" src="https://community.plus.net/html/@5CA762C7B9B1D4AB36AAB959133ED0B4/images/emoticons/angry.gif" alt="Angry" title="Angry" /&gt;</description>
      <pubDate>Wed, 15 May 2013 09:00:21 GMT</pubDate>
      <guid>https://community.plus.net/t5/Plusnet-Feedback/PlusNet-Firewall-Port-Blocking-Suggestions/m-p/988720#M40740</guid>
      <dc:creator>npr</dc:creator>
      <dc:date>2013-05-15T09:00:21Z</dc:date>
    </item>
    <item>
      <title>Re: PlusNet Firewall - Port Blocking Suggestions</title>
      <link>https://community.plus.net/t5/Plusnet-Feedback/PlusNet-Firewall-Port-Blocking-Suggestions/m-p/988721#M40741</link>
      <description>That's hardly a Rant, and as I said in reply #7 it is very basic, so if your suggestion was used to Upgrade it, that would be good!</description>
      <pubDate>Wed, 15 May 2013 09:15:42 GMT</pubDate>
      <guid>https://community.plus.net/t5/Plusnet-Feedback/PlusNet-Firewall-Port-Blocking-Suggestions/m-p/988721#M40741</guid>
      <dc:creator>Anotherone</dc:creator>
      <dc:date>2013-05-15T09:15:42Z</dc:date>
    </item>
    <item>
      <title>Re: PlusNet Firewall - Port Blocking Suggestions</title>
      <link>https://community.plus.net/t5/Plusnet-Feedback/PlusNet-Firewall-Port-Blocking-Suggestions/m-p/988722#M40742</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;Quote from: Anotherone&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;That's hardly a Rant, &lt;BR /&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/BLOCKQUOTE&gt;&lt;BR /&gt;What I left unsaid was &lt;img class="lia-deferred-image lia-image-emoji" src="https://community.plus.net/html/@0FA1396AC0773F33E2DC472BB4F75D3C/images/emoticons/wink.gif" alt="Wink" title="Wink" /&gt;&lt;BR /&gt;In truth I'm disgusted with PN for promising the following which "safe surf" can not possibly deliver.&lt;BR /&gt;&lt;BLOCKQUOTE&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;Quote&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;" Set My Safe Surf Option&lt;BR /&gt;Turning on Safe Surf gives you added online security by blocking unwanted network traffic. It stops access to Peer-to-Peer software or binary USENET on your account, but still lets you get online to surf, chat, email and play games."&lt;BR /&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/BLOCKQUOTE&gt;&lt;BR /&gt;May have been true 20 years ago but not now.</description>
      <pubDate>Wed, 15 May 2013 09:34:15 GMT</pubDate>
      <guid>https://community.plus.net/t5/Plusnet-Feedback/PlusNet-Firewall-Port-Blocking-Suggestions/m-p/988722#M40742</guid>
      <dc:creator>npr</dc:creator>
      <dc:date>2013-05-15T09:34:15Z</dc:date>
    </item>
    <item>
      <title>Re: PlusNet Firewall - Port Blocking Suggestions</title>
      <link>https://community.plus.net/t5/Plusnet-Feedback/PlusNet-Firewall-Port-Blocking-Suggestions/m-p/988723#M40743</link>
      <description>But it does go on to say (at the bottom of the page)&lt;BR /&gt;&lt;BLOCKQUOTE&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;Quote&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Please note: We can’t guarantee that Safe Surf will block all Peer-to-Peer and USENET traffic. Some Peer-to-Peer applications can be set to use a different port if the common port is blocked.&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/BLOCKQUOTE&gt;&lt;BR /&gt;but that's not really an excuse for not upgrading it, especially these days when attacks are getting more sophisticated!</description>
      <pubDate>Wed, 15 May 2013 09:41:01 GMT</pubDate>
      <guid>https://community.plus.net/t5/Plusnet-Feedback/PlusNet-Firewall-Port-Blocking-Suggestions/m-p/988723#M40743</guid>
      <dc:creator>Anotherone</dc:creator>
      <dc:date>2013-05-15T09:41:01Z</dc:date>
    </item>
    <item>
      <title>Re: PlusNet Firewall - Port Blocking Suggestions</title>
      <link>https://community.plus.net/t5/Plusnet-Feedback/PlusNet-Firewall-Port-Blocking-Suggestions/m-p/988724#M40744</link>
      <description>@&lt;B&gt;npr&lt;/B&gt;,&amp;nbsp; unfortunately I have never investigated P2P so can't help any further with this discussion, but is it worth you outlining here what you would consider adequate measures and how it might be done, so that we can discuss and compare that with the existing "Safe Surf" feature, and try and encourage Plusnet to improve it in such a way that you and other forum contributors would like to see P2P blocking implemented.</description>
      <pubDate>Wed, 15 May 2013 10:27:37 GMT</pubDate>
      <guid>https://community.plus.net/t5/Plusnet-Feedback/PlusNet-Firewall-Port-Blocking-Suggestions/m-p/988724#M40744</guid>
      <dc:creator>Anonymous</dc:creator>
      <dc:date>2013-05-15T10:27:37Z</dc:date>
    </item>
    <item>
      <title>Re: PlusNet Firewall - Port Blocking Suggestions</title>
      <link>https://community.plus.net/t5/Plusnet-Feedback/PlusNet-Firewall-Port-Blocking-Suggestions/m-p/988725#M40745</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;Quote from: Anotherone&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;But it does go on to say (at the bottom of the page)&lt;BR /&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/BLOCKQUOTE&gt;&lt;BR /&gt;Yes, for me, that just confirms Plusnet know they are over egging their description of what "safe surf" will do.&amp;nbsp; &lt;img class="lia-deferred-image lia-image-emoji" src="https://community.plus.net/html/@0D61218B4C14ADFBC10BECD1C628E66A/images/emoticons/undecided.gif" alt="Undecided" title="Undecided" /&gt;&lt;BR /&gt;@purleigh&lt;BR /&gt;Sorry that's getting beyond&amp;nbsp; my experience.&lt;BR /&gt;I do know it's beyond a simple port blocking firewall though.&lt;BR /&gt;</description>
      <pubDate>Wed, 15 May 2013 12:45:12 GMT</pubDate>
      <guid>https://community.plus.net/t5/Plusnet-Feedback/PlusNet-Firewall-Port-Blocking-Suggestions/m-p/988725#M40745</guid>
      <dc:creator>npr</dc:creator>
      <dc:date>2013-05-15T12:45:12Z</dc:date>
    </item>
  </channel>
</rss>

