Skip Links

Network World

  • Social Web 
  • Email 
  • Close

Ignore the port 80 black hole at your peril

Don’t lose control of port 80
Wide Area Networking Alert By Steve Taylor and Jim Metzler , Network World , 09/06/2007
Steve Taylor
Sign up for this newsletter now!

WAN experts Steve Taylor and Jim Metzler analyze and share best practices on WAN issues from optimization to management.

  • Share/Email
  • Comment
  • Print

Even though Steve was trained as a physicist, we usually spend more time in this newsletter discussing topics such as application delivery than we do talking about physics. In this newsletter we get to discuss both.

Let’s start with application delivery. As previous newsletters have pointed out, managing application performance in general, and identifying the applications that are running on a network in particular, are both very complex tasks. There are, however, some factors that we have not previously discussed that make these tasks even more difficult. One of those is the volume of traffic that runs undetected over port 80. This is sometimes referred to as the port 80 blind spot.

Now let’s switch (briefly) to physics. According to Wikipedia, a black hole is a region of space whose gravitational field is so powerful that nothing can escape it once it has fallen past a certain point. Given the growing volume of traffic that typically transits port 80 combined with the risk associated with not being able to manage that traffic we feel justified in calling this phenomena the port 80 black hole.

As a point of reference, in TCP/IP and UDP networks a port is an endpoint to a logical connection and is numbered from 0 to 65535. The ports that are numbered from 0 to 1023 are reserved for privileged services and are designated as well-known ports. For example, port 80 is the port that the server listens to expecting to receive data from Web clients.

Some applications, however, have the ability to hop between ports. A good example of this is instant messaging software such as AOL’s Instant Messenger (AIM). AOL has been assigned ports 5190 – 5193 for its Internet traffic and AIM is typically configured to use these ports. If these ports are blocked, however, AIM will use port 80. As a result, a network manager might well think that by blocking ports 5190 – 5193 they are blocking the use of AIM when in reality they are not.

Skype is a well-known, peer-to-peer based IP telephony and IP video service. Many peer-to-peer applications, including Skype, change the port that they use each time they start. In addition, Skype is particularly adept at port-hopping with the aim of traversing enterprise firewalls. Entering via UDP, TCP, or even TCP on port 80, Skype is usually very successful at passing typical firewalls.

Steve Taylor is president of Distributed Networking Associates and publisher/editor-in-chief of Webtorials. Jim Metzler is vice president of Ashton, Metzler & Associates.

  • Share/Email
  • Comment
  • Print
Partner Content

Simplify Your Branch Infrastructure

Learn how to simplify your branch infrastructure while dramatically increasing app performance with Citrix Branch Repeater.

Download the Free Info Kit

Next-Gen Load Balancing

Free Guide: "Next Gen Load Balancing: 8 Things You Need to Handle Today's Network Traffic" shows you the functionality needed in your next load balancer.

Download the Free Guide

Accelerate Your Web Apps by up to 5x

Free Guide: "The Secret to Getting Maximum Speed from your Web Applications." Learn how you can deliver Web apps up to 5x faster.

Download the Free Guide

Comments (1)
Login
Forgot your account info?

RE: Ignore the port 80 black hole at your perilBy pjbrockmann on September 6, 2007, 10:06 amI had no idea that port 80 was such 'default' bypass to port blocking techniques. Are there techniques to scan the app types at port 80?

Reply | Read entire comment

View all comments

Add comment
Anonymous comments subject to approval. Register here for member benefits.
Have a NetworkWorld account? Log in here. Register now for a free account.

Videos

rssRss Feed

Whitepapers

Overcoming Single Provider MPLS Limitations

In this whitepaper paper, Stratecast Partners reviews the limitations associated with a single...

Global IT Integration Strategies for Mergers, Acquisitions & Divestitures

One of the most critical success factors for a merger, acquisition or divestiture is how quickly...

Windows Vista: Necessity and Opportunity

The Vista era of Windows is here. Yet most organizations will retain Windows XP alongside new Vista...

Webcasts

Migrating to Windows Vista: Necessity and Opportunity

The Vista era of Windows is here. Yet most organizations will retain Windows XP alongside new Vista...

CX4: Leading-Edge Midrange Storage for Virtualized Environments

View this webcast and learn how you can enjoy next-generation innovation with UltraFlex technology,...

PoE Plus: Impact on the PoE Market

The standard for Power over Ethernet (PoE), IEEE Std. 802.3af(tm)-2003, advanced networking,...

Special Reports

Get More From Your WAN

Download this Network World Executive Guide and get information that details how real-world...

WAN Optimization: How to rev up sluggish applications

WAN optimization technology is maturing and buyers are more comfortable than ever with tools that...

Network World Executive Guide: Perfecting Application Performance Management

Application performance-management vendors are dangling a new carrot in front of network executives...

Get instant email notification when white papers, webcasts, executive guides are added to our library. Stay informed and up-to-date with the latest on IT Technologies with Network World's Resource Alerts.
Network World,to go. Wherever you are. Breaking news delivered to your mobile device. Select the hottest topics in networking and start receiving Network World on your mobile device today.