View Single Post
Old 10-24-2007, 01:41 PM   #6
Aroc
CrackBerry Addict
 
Join Date: Jul 2005
Location: Solon, OH, USA
Model: 9000
OS: 4.6.0.167
PIN: 20878533
Carrier: ATT
Posts: 708
Default

The Notes client and Domino server support encrypted communications. That along with enabling "Compare Notes public keys against those stored in Directory" should keep you mostly protected. I have no qualms about leaving 1352 open to the outside world in that case since the attacker would need a valid, certified user ID file (and a valid password for that file).

As for the original post, yes, we too are starting to see port TCP 1352 being blocked more and more these days. Strangely some hotels (outside north america) may block TCP 1352 from guest rooms, but that port may be wide-open in the common lobby areas. We're also seeing the same thing (TCP 1494, TCP 2598 etc for Citrix) on other ports. It seems that in some cases a lot of traffic other than the known web ports are starting to be blocked with increasing frequency. Add to that some places that appear to drop IPsec traffic, effectively killing VPN. So sometimes even opening a VPN tunnel back to the office does not work.

But in all fairness, the frequency of seeing IPsec traffic (VPN) dropped is much less often today than it was say 4-5 years ago, when it seemed that several consumer broadband providers were dropping IPsec, suggesting instead, our telecommuters should opt for >$100/mo "business class" packages.
__________________
--
Domino 7.0.4FP1 | BES 4.1.6 MR-7 | 42 handhelds
Offline   Reply With Quote