Re: Pix ASA hide ports for portscan?



Edwin schrieb:
Hi All,

I have configured a Pix ASA and opened some ports to dmz and inside for e.g. mail, www and rdp.

Is it possible to have the pix hide these open ports from portscans originated from outside? If so, how can it be done?

Can be done by ACL denying access to these ports or by shutting down the WAN interface ;-) This is most probably not what you want.

If your PIX refuses to connect to the port the listener of the daemon of DMZ' server will not be reachable anymore from the outside This is due to the nature of tcp and not related to any special firewall.

--
Uli
.



Relevant Pages

  • RE: Exhange 2003
    ... Is the PIX smtp fixup protocol enabled? ... > and when the Exchange server actually presented it's 220 banner. ... no restriction on ports or types of traffic just on host... ... >>But if you open a tcp connection and after that run nbtstat command, ...
    (Pen-Test)
  • Re: Pix ASA hide ports for portscan?
    ... Is it possible to have the pix hide these open ports from portscans ... DMZ' server will not be reachable anymore from the outside This is due ...
    (comp.dcom.sys.cisco)
  • Re: exchange being switched to static ports due to firewall
    ... this is from memory as I ditched Cisco Pix years ago and I'm ... access-group acl_outside in interface outside ... Cisco, I have to tell exchange to use static ports, and I have to tell my ... I'm sticking a cisco 506e pix in front of my mail server which is stand ...
    (microsoft.public.exchange2000.connectivity)
  • Re: OWA front end and Cisco PIX
    ... He shouldn't have to open any ports from the FE to the BE. ... He would have to open all of those ports if the FE were in the DMZ, ... > pop3 tcp If you want ... it should be pointing to your PIX ...
    (microsoft.public.exchange.clients)
  • Re: Secure network question???
    ... that a PIX 501 is something that I can afford, Sorry, I was thinking back a ... programed a Cisco router for B-ISDN so you will still hear from me in the ... security and have a sound knowledge of reflexive ACL's. ... I don't yet know what ports that would be. ...
    (comp.dcom.sys.cisco)