|
|
Pix ASA hide ports for portscan?
Hi All,
I have configured a Pix ASA and opened some ports to dmz and inside for
e.g. mail, www and rdp.
Is it possible to have the pix hide these open ports from portscans
originated from outside? If so, how can it be done?
Thanks in advance
Edwin
|
|
0
|
|
|
|
Reply
|
Edwin
|
5/30/2008 8:49:45 AM |
|
Edwin schrieb:
> Hi All,
>
> I have configured a Pix ASA and opened some ports to dmz and inside for
> e.g. mail, www and rdp.
>
> Is it possible to have the pix hide these open ports from portscans
> originated from outside? If so, how can it be done?
Can be done by ACL denying access to these ports or by shutting down the
WAN interface ;-) This is most probably not what you want.
If your PIX refuses to connect to the port the listener of the daemon of
DMZ' server will not be reachable anymore from the outside This is due
to the nature of tcp and not related to any special firewall.
--
Uli
|
|
0
|
|
|
|
Reply
|
Uli
|
5/30/2008 10:09:01 AM
|
|
Uli Link <VonRechts.NachLinks@usenet.arcornews.de> wrote in news:483fd23d$0
$27444$9b4e6d93@newsspool4.arcor-online.net:
> Edwin schrieb:
>> Hi All,
>>
>> I have configured a Pix ASA and opened some ports to dmz and inside for
>> e.g. mail, www and rdp.
>>
>> Is it possible to have the pix hide these open ports from portscans
>> originated from outside? If so, how can it be done?
>
> Can be done by ACL denying access to these ports or by shutting down the
> WAN interface ;-) This is most probably not what you want.
>
> If your PIX refuses to connect to the port the listener of the daemon of
> DMZ' server will not be reachable anymore from the outside This is due
> to the nature of tcp and not related to any special firewall.
>
I fully agree with you. something needs to respond to requests for a
certain port.
I was actually hoping that the Pix had some feature that deals with certain
characteristics of a portscan. Portscans are recognizeable in general...but
maybe not by a pix?
|
|
0
|
|
|
|
Reply
|
Edwin
|
5/30/2008 3:20:02 PM
|
|
Edwin wrote:
>>
>
>
> I fully agree with you. something needs to respond to requests for a
> certain port.
> I was actually hoping that the Pix had some feature that deals with certain
> characteristics of a portscan. Portscans are recognizeable in general...but
> maybe not by a pix?
So I know that with IPTABLES you can do things like reject access after
certain connection attempts in a specific time frame from the same IP or
any other combination you can dream up. I presume that is what you want?
I am not sure if the PIX can do this or not.
There are millions of port scans performed on a daily basis. Its much
noise.
If I am after your network, a quick gander of the nmap manual page gives
me several ways to get around you blocking me. And I probably wouldn't
compromise your network from the same netblock I am scanning you from.
I will say that restricting access to ports can back fire on you.
If I want to give you a really bad day, I'll just hijack some CLASS C
(and maybe a couple class b) subnets and do a really aggressive NMAP
scan from a wide variety of compromised hosts and sit back and smile as
your customer support line rings off the hook. :)
I would look at rate limiting and other measures before implementing
something like automated port blocking.
If this is a Linux box you can always use portsentry. It may have been
ported to other versions of UNIX not sure.
Windows may have something similar not sure.
Charles
|
|
0
|
|
|
|
Reply
|
Charles
|
6/3/2008 7:32:17 AM
|
|
|
3 Replies
424 Views
(page loaded in 0.058 seconds)
Similiar Articles: Pix ASA hide ports for portscan? - comp.dcom.sys.ciscoHi All, I have configured a Pix ASA and opened some ports to dmz and inside for e.g. mail, www and rdp. Is it possible to have the pix hide these o... PIX 6.3.4 - Hide NAT before VPN - comp.dcom.sys.ciscoPix ASA hide ports for portscan? - comp.dcom.sys.cisco:) I would look at rate limiting and other measures before ... Ports to open to the firewall (Hide Nat, Cisco VPN ... Port blocked - Cisco router or PIX - comp.dcom.sys.cisco ...Pix ASA hide ports for portscan? - comp.dcom.sys.cisco Cisco ASA 5505 URL Blocking - comp.dcom.sys.cisco Pix ASA hide ports for portscan? - comp ... asa 5505 not nat problem - comp.dcom.sys.ciscoPix ASA hide ports for portscan? - comp.dcom.sys.cisco Ports to open to the firewall (Hide Nat, Cisco VPN) Pix ASA hide ports for portscan? ... Pix ASA hide ports for ... ASA 5510 multiple outside networks multiple IP - comp.dcom.sys ...Pix ASA hide ports for portscan? - comp.dcom.sys.cisco ASA 5510 multiple outside networks multiple IP - comp.dcom.sys ... Pix ASA hide ports for portscan ... or 7960 ... PIX ASA : Need to setup a server in a DMZ such that - comp.dcom ...We need to give certain customers the ability ... Pix ASA hide ports for portscan ... or 7960 ... User Bulletin Board Hi, is it possible to setup remote access SSL VPN in ... Request from Outside ... - comp.sys.ibm.ps2.hardwarePix ASA hide ports for portscan? - comp.dcom.sys.cisco... anymore from the outside This is due > to the nature of tcp and not related to any special firewall. > I fully ... Throttling network traffic - comp.arch.embeddedPix ASA hide ports for portscan? - comp.dcom.sys.cisco Throttling network traffic - comp.arch.embedded Hide quoted text - A number of firewalls can run ... access to a ... DNS Doctoring - comp.dcom.sys.ciscoPIX/ASA: Perform DNS Doctoring with the static ... with a cisco router - comp.dcom.sys.cisco PIX Port ... PIX 6.3.4 - Hide NAT before VPN - comp.dcom.sys.cisco DNS ... VPN client disconnects - comp.dcom.sys.cisco... and I haven't made any changes to the ASA ... Enabled VLAN Trunk Ports : 8 This platform has an ASA 5505 Security Plus ... Hide quoted t= ext - > > - Show quoted text Pix ASA hide ports for portscan? - comp.dcom.sys.cisco | Computer ...Hi All, I have configured a Pix ASA and opened some ports to dmz and inside for e.g. mail, www and rdp. Is it possible to have the pix hide these o... Stop Port Scan Replies on Cisco ASA 5505: cisco, port scan, reply, asaWe get port scanned daily from china and korea for some reason. Sadly ... Experts Exchange; Enterprise Firewalls; Cisco PIX/ASA; Stop Port Scan Replies on Cisco ASA 5505 7/25/2012 6:55:13 PM
|
|
|
|
|
|
|
|
|