Skip to content

L4 – Network Security – Firewall Policies per Service

cpx May 26, 2026 3 min read Network Services
IDNameDescriptionActionDirectionProtocolSrc PortsDst Ports
1IPSec IKEAllow (Stateful)IncomingUDP500
2IPSec AuthenticationAllow (Stateful)IncomingOther
3Domain Controller (TCP)Allow incoming traffic to a Domain ControllerAllow (Stateful)IncomingTCP119,135,139,389,445,464,500,563,593,636,1026,1067-1068,1723,3268-3269
4Domain Controller (UDP)Allow incoming traffic to a Domain ControllerAllowIncomingUDP88,137-138,389,500,1645-1646,1701,1723,1812-1813
5Web ServerAllow incoming TCP traffic to a Web ServerAllow (Stateful)IncomingTCP80,443
6Remote Access SSHAllow remote access to machinesAllow (Stateful)IncomingTCP22
7Domain Client (TCP)Allow incoming traffic from the domain controllerAllow (Stateful)IncomingTCP42,88,135,139,445,3268,3269
8Domain Client (UDP)Allow incoming traffic from the domain controllerAllowIncomingUDP53,88,137,138
9SMTP ServerAllow incoming TCP traffic to an SMTP ServerAllow (Stateful)IncomingTCP25
10IDENTAllow (Stateful)IncomingTCP113
11DNS ServerAllow incoming DNS requests to a DNS serverAllowIncomingTCP/UDP53
12ICMP Echo RequestAllow incoming Ping requestsAllowIncomingICMP
13Network Time ProtocolAllow Network Time Protocol trafficAllowIncomingUDP123
14Windows File SharingAllow file sharing trafficAllowIncomingTCP/UDP137,138,139,445
15Remote Access RDPAllow remote access to machinesAllow (Stateful)IncomingTCP3389
16POP3 ServerAllow (Stateful)IncomingTCP110
17IMAP ServerAllow (Stateful)IncomingTCP143,585,993
18Computer Associates UnicenterAllow (Stateful)IncomingTCP4105
19VeritasAllow (Stateful)IncomingTCP13722,10000,13701,6101,13782
20MySQL ServerAllowIncomingTCP/UDP3306
21WINSAllowIncomingTCP/UDP1512
22WINS RegistrationAllowIncomingTCP/UDP137
23WINS ReplicationAllowIncomingTCP/UDP42
24Restricted Interface Exceptions – Netbios Name Service IncomingAllowIncomingUDP137137
25Restricted Interface Exceptions – ARP IncomingAllowIncomingAny
26Restricted Interface EnforcementLog packets blocked due to Restricted Interface Enforcement policyDeny (Log)Outgoing/BothAny
27Off Domain Exceptions – Domain Client (TCP)AllowOutgoing/BothTCP42,88,135,139,445,3268,3269
28Off Domain Exceptions – ARPAllowOutgoing/BothAny
29Off Domain Exceptions – DNSAllowOutgoing/BothTCP/UDP53
30Remote Domain ExceptionsWhen remotely connected to domain only corporate traffic is allowedAllowOutgoing/BothTCP/UDP
31Remote Domain Enforcement (Split Tunnel)Log packets blocked due to Remote Domain Enforcement policyDeny (Log)Outgoing/BothTCP/UDP
32Off Domain EnforcementLog packets blocked due to Off Domain Enforcement policyDeny (Log)Outgoing/BothAny
33Allow PPPOE DiscoveryAllow (Stateful)IncomingAny
34Allow PPPOE SessionAllow (Stateful)IncomingAny
35Off Domain Exceptions – HTTP(S)AllowOutgoing/BothTCP80,443
36Off Domain Exceptions – ICMP Echo RequestAllowOutgoing/BothICMP
37Off Domain Exceptions – IPSec EncryptionAllowOutgoing/BothOther
38Off Domain Exceptions – VPN TunnelAllowOutgoing/BothTCP/UDP443,500,1723
39Off Domain Exceptions – Wireless AuthenticationAllowOutgoing/BothAny
40Remote Domain Exceptions – ARPAllowOutgoing/BothAny
41Remote Domain Exceptions – DNSAllowOutgoing/BothTCP/UDP53
42Remote Domain Exceptions – GREAllowOutgoing/BothOther
43Remote Domain Exceptions – ICMP Echo RequestAllowOutgoing/BothICMP
44Remote Domain Exceptions – IPSec EncryptionAllowOutgoing/BothOther
45Remote Domain Exceptions – VPN TunnelAllowOutgoing/BothTCP/UDP443,500,1723
46Restricted Interface Exceptions – ARP OutgoingAllowOutgoing/BothAny
47Restricted Interface Exceptions – DHCP Client IncomingAllowIncomingUDP67
48Restricted Interface Exceptions – DHCP Client OutgoingAllowOutgoing/BothUDP68
49Restricted Interface Exceptions – Wireless Authentication IncomingAllowIncomingAny
50Restricted Interface Exceptions – Wireless Authentication OutgoingAllowOutgoing/BothAny
51Restricted Interface Exceptions – Netbios Name Service OutgoingAllowOutgoing/BothUDP137137
52Deep Security AgentAllow incoming traffic to Deep Security AgentAllow (Stateful)IncomingTCP4118
53VMware vCenter ServerAllow incoming traffic to VMware vCenter ServerAllow (Stateful)IncomingTCP/UDP80,443,902,8443,25,53,161,162,389,445,623,636,903,1024,1433,1521,5989,6500,6501,6502,8080,8095,8096,9087,9443,10109,10111,10443,18443,27000,27010,31000,52267,57348,60099
54Allow ICMP fragmentation packet (type 3, code 4)AllowIncomingICMP
55ARPAllow incoming ARP trafficAllowIncomingAny
56Allow ICMP type 3 code 4This ICMP packet is used for MTU path negotiationAllowIncomingICMP
57Allow solicited TCP/UDP repliesUDP stateful and TCP stateful must be enabledAllow (Stateful)IncomingTCP/UDP
58Allow solicited ICMP repliesICMP stateful must be enabledAllow (Stateful)IncomingICMP
59DHCP ClientAllow DHCP Offer traffic to a DHCP ClientAllowIncomingUDP6768
60Deny Internal IP RangesIngress filter to deny incoming spoofed packetsDeny (Log)IncomingAny
61NetBios Name ServiceFor hosts that rely on NetBios for name resolutionAllowIncomingUDP137137
62DHCP ServerAllow incoming DHCP requests to a DHCP serverAllowIncomingUDP6867
63Wireless AuthenticationAllow wireless authentication trafficAllowIncomingAny
64FTP ServerAllow incoming traffic to an FTP ServerAllow (Stateful)IncomingTCP20,21
65Microsoft SQL ServerAllow incoming TCP traffic to a Microsoft SQL serverAllowIncomingTCP/UDP1433,1434
66Oracle SQL ServerAllow incoming traffic to an Oracle SQL serverAllowIncomingTCP/UDP1521,5560
67Deep Security ManagerAllow incoming traffic to Deep Security ManagerAllow (Stateful)IncomingTCP4119,4120
68Microsoft Exchange ServerAllow incoming traffic to an Microsoft Exchange ServerAllow (Stateful)IncomingTCP135,102,25,691,80,443,110,995,143,993,119,563,379,135
69IPSec EncryptionAllow (Stateful)IncomingOther
70Generic Routing EncapsulationAllow (Stateful)IncomingOther
71Off Domain Exceptions – DHCP ClientAllowOutgoing/BothUDP68
72Off Domain Exceptions – Domain Client (UDP)AllowOutgoing/BothUDP42,88,135,139,445,3268,3269
73Off Domain Exceptions – GREAllowOutgoing/BothOther

0 0 votes
Article Rating
guest

0 Comments
Oldest
Newest Most Voted
0
Would love your thoughts, please comment.x
()
x