Firewall Wizards mailing list archives
RE: False results to DMZ
From: "David U. Haltinner" <dhaltinner () altaresources com>
Date: Mon, 23 Jan 2006 08:56:06 -0600
I have tried to use different variations with sysopt proxy arp, and I have setup manual NAT's for the source machine (Both global nat as well as static nat gives same results). Doing a packet trace ont he destinations hsows the correct IP for the source, but it is sending resets like it should. The source is getting back zerowindow ACK's isntead of resets. But only the one DMZ. I have compared the setup of the DMZ's, and they are all the same. On Mon, 2006-01-23 at 09:33 -0500, Paul Melson wrote:
-----Original Message----- Subject: [fw-wiz] False results to DMZFirst off, the DMZ is setup with virtual interfaces (PIX), and thescanning source isinside. The firewall allows anything IP from this scanner. If I scan mostof the DMZ's, Iget normal results, with all of the scans. Using NMAP, If I scan one specific DMZ, I only get results with the SYNscan and TCP windowscans, AND it says every port is open (what the firewall allows). Ciscosupport is not being > helpful. Does anyone have any idea why this is? It's weird. Im trying to automate Nessusagainst the DMZ servers, and its giving too many false positives aboutopen ports.I have taken packet traces, and the only thing weird is that I am gettingan ACK back foreveyr port, but they are Zero Window (TCP Window Scan brings back everyport open).Any ideas?Can you post a sanitized version of your PIX config? Specifically I'm wondering about sysopt proxy arp and static/global nat settings. If you scan with nmap -sT (full TCP connect() scan) do you get correct results? PaulM
_______________________________________________ firewall-wizards mailing list firewall-wizards () honor icsalabs com http://honor.icsalabs.com/mailman/listinfo/firewall-wizards
Current thread:
- False results to DMZ David U. Haltinner (Jan 20)
- RE: False results to DMZ Paul Melson (Jan 23)
- RE: False results to DMZ David U. Haltinner (Jan 23)
- <Possible follow-ups>
- RE: False results to DMZ Ralf . Zessin (Jan 24)
- RE: False results to DMZ David U. Haltinner (Jan 24)
- RE: False results to DMZ Paul Melson (Jan 23)