Which Outbound Ports to Block?
For Example, the Sans Institute Recommends Blocking Outbound Traffic That Uses the Following Ports: Ms Rpc – Tcp & Udp Port 135. Netbios/Ip – Tcp & Udp Ports...
- MS RPC – TCP & UDP port 135.
- NetBIOS/IP – TCP & UDP ports 137-139.
- SMB/IP – TCP port 445.
- Trivial File Transfer Protocol (TFTP) – UDP port 69.
- Syslog – UDP port 514.
Should you block outbound traffic?
Blocking outbound traffic is usually of benefit in limiting what an attacker can do once they've compromised a system on your network. Blocking outbound traffic can help stop this from happening, so it's not so much stopping you getting infected as making it less bad when it's happened.
Should I block port 113?
The good news is that since IDENT is almost never used, simple "hard stealthing" of port 113, which is available from all personal firewalls, is probably sufficient. It will allow your system to remain completely invisible on the Internet and will almost certainly never cause any connection trouble.