Switch to Linear ModeSwitch to Hybrid ModeSwitch to Threaded Mode
Printer Friendly View | Email this page | Register Now to enjoy user benefits!
FoxTwo
FoxTwo's Avatar
Clanless and guildless
Join Date: Jan 2006
Location: Singapore
Posts: 480
Trade rep: 0%
uPnP vs Portforward FoxTwo Apr 12th, 07, 11:30 AM #1 (permalink)
Hi guys...

Just wondering which method you guys actually prefer and use?

For example, for me, I try not to port-forward whenever possible, ie let the application use uPnP to open ports etc.

My reasons for preferring uPnP
====================

1) uPnP does not require static IPs
2) If you have more than 1 PC/laptop on the same network, they all can use the same application/game at the same time. uPnP will take care of the ports etc automatically.
3) No "permanent hole" in the router firewall. Application will close the opened port when it has done its thing (usually heheh!)
4) Easier for people to connect to your wireless network you don't have to configure anything for them.

 
xrM
xrM's Avatar
\//\\/\//\
Join Date: Jun 2005
Location: IP3023
Posts: 9,464
Trade rep: 100%
Thanked 1 Times in 1 Post
xrM Apr 12th, 07, 01:03 PM #2 (permalink)
UPnP - http://www.grc.com/unpnp/unpnp.htm
DMZ - Don't even touch it, it's dangerous. Use the other two options..
Intel Xeon E3110 → MSI P35 Neo2-Fr → XV 9600GT → Corsair XMS2 1GBx2 → WD 160GB Seagate 320GB → LG GH20N 20X SATA → CoolerMaster M520 → 19' AL1914 LCD

Quote:
I think that its God's cruel joke to have so many of us ugly people in the world and then try to tell us its "what's on the inside" that counts."
 
p|sangp|sang
p|sangp|sang's Avatar
I ish <3 kinpatsu rori
Join Date: Dec 2004
Location: Errecting a dispenser!
Posts: 41,744
Trade rep: 100%
Thanked 1 Times in 1 Post
p|sangp|sang Apr 12th, 07, 01:56 PM #3 (permalink)
pros of upnp
1) stright forward
2) zero cfg
cons
1) no ways of knowing wat port has been forward
so far i only see ddwrt has this feature of listing out active upnp-ed ports

Quote:
3) No "permanent hole" in the router firewall. Application will close the opened port when it has done its thing (usually heheh!)
ammend abit here. the port will remain open when the application is running n closed when application is running.

simmilar can be said with PF. eventhough it has set to open permently, but if the application issnt running(not in listening) ingress traffic will be denied.

Civilization is over, It's time to Elect The Dead.
 
p|sangp|sang
p|sangp|sang's Avatar
I ish <3 kinpatsu rori
Join Date: Dec 2004
Location: Errecting a dispenser!
Posts: 41,744
Trade rep: 100%
Thanked 1 Times in 1 Post
p|sangp|sang Apr 12th, 07, 02:00 PM #4 (permalink)
Quote:
Originally Posted by xrM
DMZ - Don't even touch it, it's dangerous. Use the other two options..
not as dangerous as u think. its just like plugging your pc directly to your modem, deffinatly are using some sort of firewall

Civilization is over, It's time to Elect The Dead.
 
FoxTwo
FoxTwo's Avatar
Clanless and guildless
Join Date: Jan 2006
Location: Singapore
Posts: 480
Trade rep: 0%
FoxTwo Apr 12th, 07, 02:07 PM #5 (permalink)
Quote:
Originally Posted by P|saNgP|saNg
cons
1) no ways of knowing wat port has been forward
so far i only see ddwrt has this feature of listing out active upnp-ed ports
Actually my router (Netgear WGR 614v4) can see in the router web admin page. Also, there's an icon on my system tray called "Residential Gateway" or "Internet Connection" (depending on which PC). Double click that, look at properties, it tells you exactly which port has been open by which application on which PC.

 
xrM
xrM's Avatar
\//\\/\//\
Join Date: Jun 2005
Location: IP3023
Posts: 9,464
Trade rep: 100%
Thanked 1 Times in 1 Post
xrM Apr 12th, 07, 02:49 PM #6 (permalink)
Quote:
Originally Posted by P|saNgP|saNg
not as dangerous as u think. its just like plugging your pc directly to your modem, deffinatly are using some sort of firewall
And if you disabled your windows firewall and forgot to reenable it after putting your computer in a DMZ , you're screwed
Intel Xeon E3110 → MSI P35 Neo2-Fr → XV 9600GT → Corsair XMS2 1GBx2 → WD 160GB Seagate 320GB → LG GH20N 20X SATA → CoolerMaster M520 → 19' AL1914 LCD

Quote:
I think that its God's cruel joke to have so many of us ugly people in the world and then try to tell us its "what's on the inside" that counts."
 
p|sangp|sang
p|sangp|sang's Avatar
I ish <3 kinpatsu rori
Join Date: Dec 2004
Location: Errecting a dispenser!
Posts: 41,744
Trade rep: 100%
Thanked 1 Times in 1 Post
p|sangp|sang Apr 12th, 07, 02:54 PM #7 (permalink)
Quote:
Originally Posted by FoxTwo
Actually my router (Netgear WGR 614v4) can see in the router web admin page. Also, there's an icon on my system tray called "Residential Gateway" or "Internet Connection" (depending on which PC). Double click that, look at properties, it tells you exactly which port has been open by which application on which PC.
oo didnt know tt. another way i found out is to look under the log or active connections tabs.

Civilization is over, It's time to Elect The Dead.
 
p|sangp|sang
p|sangp|sang's Avatar
I ish <3 kinpatsu rori
Join Date: Dec 2004
Location: Errecting a dispenser!
Posts: 41,744
Trade rep: 100%
Thanked 1 Times in 1 Post
p|sangp|sang Apr 12th, 07, 02:55 PM #8 (permalink)
Quote:
Originally Posted by xrM
And if you disabled your windows firewall and forgot to reenable it after putting your computer in a DMZ , you're screwed
o'really? my machine is dmzed with no firewall wat so ever. so how come im still unscrewed?

Civilization is over, It's time to Elect The Dead.
 
martinchua
martinchua's Avatar
Registered User
Join Date: Aug 2005
Posts: 55,357
Trade rep: 100%
martinchua Apr 12th, 07, 03:18 PM #9 (permalink)
how dangerous can dmz without firewall be?

im on dmz without firewall too.
 
xrM
xrM's Avatar
\//\\/\//\
Join Date: Jun 2005
Location: IP3023
Posts: 9,464
Trade rep: 100%
Thanked 1 Times in 1 Post
xrM Apr 12th, 07, 04:19 PM #10 (permalink)
Well, it's as bad as having no firewall and no router to protect you. You find that ok, then it's ok..
Intel Xeon E3110 → MSI P35 Neo2-Fr → XV 9600GT → Corsair XMS2 1GBx2 → WD 160GB Seagate 320GB → LG GH20N 20X SATA → CoolerMaster M520 → 19' AL1914 LCD

Quote:
I think that its God's cruel joke to have so many of us ugly people in the world and then try to tell us its "what's on the inside" that counts."
 
thetarget
thetarget's Avatar
Squrfer
Join Date: Apr 2006
Posts: 1,659
Trade rep: 0%
thetarget Apr 12th, 07, 05:18 PM #11 (permalink)
DMZ basically is all-ports-belong-to-me mode.
It opens all port, forward it to the IP assigned.

Errors occurs when changes are rejected. Since nothing is stopping the connections going in/out your network, I won't be questioning your confidence level. Not implying that you will get errors, only that you would.

I won't be touching UPnP for many reasons, much of which is related to the infamous incident. Port forwarding havn't give me any problem, so I've stayed with it
"No comments", he commented.
Anti-spam:
Quote:
you are spamming because:

a) You didn't read the forum rules.
b) Rules don't apply to you, you're omni-potent.
c) You can't read the forum rules.
d) Annoying the people you want help from doesn't matter to you in the least.
e) All of the above.
f) Most of the above.

Pick the most correct answer and most of all - STOP DOUBLE-POSTING.
 
John_Chee
John_Chee's Avatar
Registered User
Join Date: Dec 2004
Posts: 6,989
Trade rep: 0%
John_Chee Apr 12th, 07, 05:49 PM #12 (permalink)
So which is better to do portforwarding or UPnP? I am currently playing around with portforwarding on my network to open up the port for my bitcomet.
 
PsyNidE
PsyNidE's Avatar
UnLocKed AccOunT
Join Date: Feb 2005
Location: uNdeR dA sEa
Posts: 7,349
Trade rep: 100%
PsyNidE Apr 12th, 07, 06:34 PM #13 (permalink)
I'd rather do port forwarding or port triggering rather than UPnP ... go to www.grc.com to read about UPnP dangers
Freelance Recovery Activities Currently Suspended Till Further Notice Due To Busy Work Schedules.
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Please accept my humble apologies for any inconvenienced caused.
 
PsyNidE
PsyNidE's Avatar
UnLocKed AccOunT
Join Date: Feb 2005
Location: uNdeR dA sEa
Posts: 7,349
Trade rep: 100%
PsyNidE Apr 12th, 07, 06:36 PM #14 (permalink)
Quote:
Originally Posted by martinchua
how dangerous can dmz without firewall be?

im on dmz without firewall too.
its the same as having your house w/o a door and a gate.Any tom.dick and harry could enter and leave.
Freelance Recovery Activities Currently Suspended Till Further Notice Due To Busy Work Schedules.
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Please accept my humble apologies for any inconvenienced caused.
 
FoxTwo
FoxTwo's Avatar
Clanless and guildless
Join Date: Jan 2006
Location: Singapore
Posts: 480
Trade rep: 0%
FoxTwo Apr 12th, 07, 07:56 PM #15 (permalink)
The dangers of uPnP is overrated, IMO.

Quote:
Translating eEye's and Microsoft's statements into consequences, this means that without the security update patch, and with the Universal Plug and Play (UPnP) system in its default "enabled" state, any of the many millions of Internet-connected UPnP-equipped Windows systems could be remotely commandeered and forced to download and run any malicious code of a hacker's design. This includes using the machine to launch potent Denial of Service (DoS) and Distributed Denial of Service (DDoS) attacks.


It's dangerous only if you had installed WinXP (prior to SP1), and totally never patched it via WindowsUpdate function since.

Even so, with a properly configured firewall this can be overcome. For example I have been running WinXP with only SP1 for years until 2006 when I decided to get off my lazy butt and install SP2 (cos some apps I wanted to run REQUIRED the #&$#^&@ SP2!)

Remember, the problem of uPnP was discovered in 2001. It's now 2007. Six years have passed.

While I'm not saying that being cautious about uPnP and not using it is wrong, port-forwarding has its own set of dangers too. You just have to weigh which danger is less of a risk to you.

The safest, of course, is not to connect to the Internet at all



 
Last edited by FoxTwo; Apr 12th, 07 at 07:59 PM..
Thread Tools Display Modes
Linear Mode Linear Mode
Find the best hotel rates here:
Destination:

City:

Check in Date:


Nights:
Rooms:
Adult(s):
Children:
travel.vr-zone.com
OCZ Fan Club!
OCZ Fan Club 21 OCZ Fans!
Win Visa GiftCard
Win Visa Gift Card