Re: Pix ASA hide ports for portscan?



Uli Link <VonRechts.NachLinks@xxxxxxxxxxxxxxxxxxx> wrote in news:483fd23d$0
$27444$9b4e6d93@xxxxxxxxxxxxxxxxxxxxxxxxxxx:

Edwin schrieb:
Hi All,

I have configured a Pix ASA and opened some ports to dmz and inside for
e.g. mail, www and rdp.

Is it possible to have the pix hide these open ports from portscans
originated from outside? If so, how can it be done?

Can be done by ACL denying access to these ports or by shutting down the
WAN interface ;-) This is most probably not what you want.

If your PIX refuses to connect to the port the listener of the daemon of
DMZ' server will not be reachable anymore from the outside This is due
to the nature of tcp and not related to any special firewall.



I fully agree with you. something needs to respond to requests for a
certain port.
I was actually hoping that the Pix had some feature that deals with certain
characteristics of a portscan. Portscans are recognizeable in general...but
maybe not by a pix?

.



Relevant Pages

  • RE: Exhange 2003
    ... Is the PIX smtp fixup protocol enabled? ... > and when the Exchange server actually presented it's 220 banner. ... no restriction on ports or types of traffic just on host... ... >>But if you open a tcp connection and after that run nbtstat command, ...
    (Pen-Test)
  • Re: exchange being switched to static ports due to firewall
    ... this is from memory as I ditched Cisco Pix years ago and I'm ... access-group acl_outside in interface outside ... Cisco, I have to tell exchange to use static ports, and I have to tell my ... I'm sticking a cisco 506e pix in front of my mail server which is stand ...
    (microsoft.public.exchange2000.connectivity)
  • Re: OWA front end and Cisco PIX
    ... He shouldn't have to open any ports from the FE to the BE. ... He would have to open all of those ports if the FE were in the DMZ, ... > pop3 tcp If you want ... it should be pointing to your PIX ...
    (microsoft.public.exchange.clients)
  • Re: Secure network question???
    ... that a PIX 501 is something that I can afford, Sorry, I was thinking back a ... programed a Cisco router for B-ISDN so you will still hear from me in the ... security and have a sound knowledge of reflexive ACL's. ... I don't yet know what ports that would be. ...
    (comp.dcom.sys.cisco)
  • Re: Adding a second NIC
    ... Then I just need to open the proper ports on the PIX... ... The PIX Firewall/Router has a Public and a Private side. ... SBS External NIC, 192.168.0.2 ... DNS for the external NIC will point to the SBS server ...
    (microsoft.public.windows.server.sbs)