Wednesday, May 1, 2024
 Popular · Latest · Hot · Upcoming
5
rated 0 times [  5] [ 0]  / answers: 1 / hits: 24597  / 1 Year ago, sun, january 15, 2023, 4:29:00

I have installed the gufw firewall utility and want to make a whitelist of ports (want maximum security, but whitelisting single IPs is currently too tedious). I have so far only entered ports 53 (for DNS), 80 (for HTTP) and 443 (for HTTPS), both in- and outgoing, into the whitelist and closed the firewall, but Ubuntu Software Center can install programs without hindrance, whereas the firewall definitely is running (www content won't load when list entries are not present).



Is it using any of these ports for program data transfer? Seems strange to me. Or is there an overriding exception pre-defined in Ubuntu (this is a new setup, 12.04)? What is probably the case here, and what port does the Software Center use for program data (I assume it does use HTTP for the interface and list entries, but the programs themselves?)?



TLDR:




  1. Why does Ubuntu Software Center get through my firewall which blocks all but DNS/HTTP/HTTPS (via blocking all other ports), so that it can install programs?


  2. Which port does it use for the program data transfer?



More From » networking

 Answers
6

Here's what I found out by running Wireshark while installing a single application using the Ubuntu Software Centre:




  • DNS requests (outgoing to UDP port 53 to your configured DNS server, for...) and HTTP (outgoing to TCP port 80 to...)

    • reviews.ubuntu.com

    • myapps.developer.ubuntu.com

    • software-center.ubuntu.com


  • Everything about your local APT configuration (repositories configured). This is usually either HTTP or FTP and requires DNS as well of course. See your "Software Sources" to see what Ubuntu archives mirror you're using. If you can run sudo apt-get update without errors, you're all set.



Note: I did not find any HTTPS traffic. However, this may be the case for private PPAs (used for commercial software).


[#32884] Sunday, January 15, 2023, 1 Year  [reply] [flag answer]
Only authorized users can answer the question. Please sign in first, or register a free account.
gliroopy

Total Points: 290
Total Questions: 115
Total Answers: 114

Location: Egypt
Member since Tue, May 3, 2022
2 Years ago
;