Showing posts with label Security. Show all posts
Showing posts with label Security. Show all posts

Saturday, February 1, 2014

Useful Network Port Number

FTP - 20 TCP (Data), 21 TCP (Command)
TFTP - 69 UDP
SFTP - 115 TCP
SSH - 22 TCP
TELNET - 23 TCP
DNS - 53 TCP/UDP
DHCP - 67 UDP (Server), 68 UDP (Client)
DHCPv6 - 546 TCP/UDP (Client), 547 TCP/UDP (Server)
KERBEROS - 88 TCP/UDP
NNTP - 119 TCP
NTP - 123 UDP
NETBIOS - 137 TCP/UDP (Name), 138 TCP/UDP (Datagram), 139 TCP/UDP (Session)
SNMP - 161 UDP, 162 UDP (Trap)

SMB - 445 TCP

HTTP - 80 TCP
HTTPS - 443 TCP/UDP

SMTP - 25 TCP
POP3 - 110 TCP
POP3S - 995 TCP
IMAP - 143 TCP
IMAPS - 993 TCP

KERBEROS PASSWORD - 464 TCP/UDP
RIP - 520 UDP

SQL Server - 1433 TCP/UDP (Server), 1434 TCP/UDP (Monitor)
MYSQL - 3306 TCP/UDP

PPTP - 1723 TCP
L2TP - 1701 UDP, 500 UDP (ISAKMP), 4500 UDP (IPSec NAT Traversal), 50AH, 51ESP
RADIUS - 1812 UDP (Authentication), 1813 UDP (Accounting)

LDAP - 389 TCP/UDP
LDAPS - 636 TCP/UDP
LDAP GC - 3268 TCP/UDP
LDAP GCS - 3269 TCP/UDP

SUPPORT ADMINISTRATION REMOTELY - 2535
REMOTE DESKTOP - 3389 TCP/UDP
TERREDO - 3544 UDP
EVENT VIEWER FORWARDING - 5985 TCP, 5986 TCP
WSUS - 8530

Sunday, January 26, 2014

Configuring WPA-EAP Authentication

This post outlines how to configure NPS RADIUS to centrally manage wireless authentication request got from wireless access point.

The test environment includes one windows server 2008 r2, one window 7 and dlink dir-632 wireless router (work as ap). Server and client should be joined to domain.

To configure dlink wireless router work as ap:
1. disable upnp in advanced -> advanced network
2. disable wps in advanced -> wifi-protected setup
3. setup static ip address for the router in setup -> network setttings
4. manually setup wireless settings in setup -> wireless settings
    (ssid, wpa-eap, radius ip, shared secret)

To configure WPA-EAP authentication:
1. Create wireless users group and add wireless users and computers in the group.
2. Install and configure NPS
    (ADDS, ADCS, Network Policy And Access Service, NPS)
3. Create RADIUS server for 802.1x wireless or wired connection
4. Register server in AD
5. Create a new wireless network policy for windows vista and later release in group policy editor.
6. Enable Certificate Services Client - Auto-Enrollment
7. Select Define These Policy Settings in Certificate Path Validation Settings

Then run gpupdate /force on windows 7 client and try to connect to the wireless network. Guess what, I failed to connect into the network. After hours debug and troubleshooting, I finally found the root cause. My test wireless adapter couldn't support WPA-Enterprise!

See video reference.