firewall config?

If you're new to FAH and need help getting started or you have very basic questions, start here.

Moderators: Site Moderators, FAHC Science Team

Post Reply
madevries
Posts: 5
Joined: Mon Jun 27, 2011 4:16 pm

firewall config?

Post by madevries »

I didn't find the FAQ on firewall configuration helpful (it just said to configure your firewall! haha). So I'm needing to know the correct destination addresses and what protocols to open up for those destinations for my client to work?
MtM
Posts: 1579
Joined: Fri Jun 27, 2008 2:20 pm
Hardware configuration: Q6600 - 8gb - p5q deluxe - gtx275 - hd4350 ( not folding ) win7 x64 - smp:4 - gpu slot
E6600 - 4gb - p5wdh deluxe - 9600gt - 9600gso - win7 x64 - smp:2 - 2 gpu slots
E2160 - 2gb - ?? - onboard gpu - win7 x32 - 2 uniprocessor slots
T5450 - 4gb - ?? - 8600M GT 512 ( DDR2 ) - win7 x64 - smp:2 - gpu slot
Location: The Netherlands
Contact:

Re: firewall config?

Post by MtM »

Hello madevries ( dutch? ) welcome to the forums.

The v6.xx clients use port 80 and 8080 just like any browser ( http ), you don't need to configure anything if you can view these forums.
madevries
Posts: 5
Joined: Mon Jun 27, 2011 4:16 pm

Re: firewall config?

Post by madevries »

Hi,

Yep, Dutch background :)

Is there a list of destination addresses/URLs to open up 80/8080 to though? I keep a very tight network...I don't want to allow outbound 80/8080 to * and I don't want to be adding URLs/hostnames to my exceptions list every time a package upload/download fails and needs it added (doable, but tedious...).

Thanks,
md
madevries
Posts: 5
Joined: Mon Jun 27, 2011 4:16 pm

Re: firewall config?

Post by madevries »

Wait a tic...That doesn't make sense eh? Of course I have outbound 80 open to all. It must be 8080 or web filtering stopping things. No worries, I'll watch for 80/8080 traffic being dropped in my logs and go from there.
madevries
Posts: 5
Joined: Mon Jun 27, 2011 4:16 pm

Re: firewall config?

Post by madevries »

Yep...It was my http filtering...Cheers! I'm "Folding @ Home" now hehe :)
bruce
Posts: 20910
Joined: Thu Nov 29, 2007 10:13 pm
Location: So. Cal.

Re: firewall config?

Post by bruce »

FAH's first choice is port 8080 and it's a good idea to have it open to quite a number of servers. If port 8080 fails, FAH will use port 80 for a second choice so it's sufficient to to have port 80 open to * but there will be some cases where your assignments may be more limited.

Depending on which client you use, FAH may also use a variety of ports to talk to other FAH processes on your local machine but those ports generally shouldn't be opened to the internet unless you want to do something more exotic like monitoring a remote FAH client.
MtM
Posts: 1579
Joined: Fri Jun 27, 2008 2:20 pm
Hardware configuration: Q6600 - 8gb - p5q deluxe - gtx275 - hd4350 ( not folding ) win7 x64 - smp:4 - gpu slot
E6600 - 4gb - p5wdh deluxe - 9600gt - 9600gso - win7 x64 - smp:2 - 2 gpu slots
E2160 - 2gb - ?? - onboard gpu - win7 x32 - 2 uniprocessor slots
T5450 - 4gb - ?? - 8600M GT 512 ( DDR2 ) - win7 x64 - smp:2 - gpu slot
Location: The Netherlands
Contact:

Re: firewall config?

Post by MtM »

Sorry madevries, lucky Bruce corrected me. Thing is, I never used a hardware firewall and every software distro I used ( pfsense being my favorite ) I never had to add 8080 manually as it was already allowed to *. It's the default alternate http port for websites and I think most software firewalls also allow traffic on 8080 to * by default. That's why it didn't occur to me to mention it explicitly, about the need to open it to get the best chance of good assignments.

Always nice to see a fellow Dutch folder, welkom bij de f@h famillie ;)

If you're really abit anal, check the Server stats and whitelist them manually, wouldn't want to do it to tedious for me :oops:
madevries
Posts: 5
Joined: Mon Jun 27, 2011 4:16 pm

Re: firewall config?

Post by madevries »

Yeah, it wasn't my firewall packet filter but rather my firewall content scanner for some reason blocking the traffic even after I opened up exceptions for all criteria to http://www.stanford.edu/* so I just disabled it temporarily to download and turned it back on once it starting crunching numbers :)
Post Reply