Solved

Scan PIX for open ports

Posted on 2004-10-11
5
334 Views
Last Modified: 2013-11-16
Can someone please tell me if there is a way to scan a PIX firewall for open ports.  Can this be done from an external location (PC, router, etc)?  Can it be done from inside the PIX?  I'm trying to verify the commands I put into the PIX to open certain ports actually opened the ports.

Thanks!!!
mEadEman
0
Comment
Question by:meade470
  • 3
  • 2
5 Comments
 
LVL 79

Expert Comment

by:lrmoore
ID: 12280552
From a client inside the PIX, go to http://www.grc.com
Run Shield's UP to test your protection..



0
 
LVL 2

Author Comment

by:meade470
ID: 12281347
Wow!  Cool page!  Is there a way to scan ports above 1023?
0
 
LVL 79

Accepted Solution

by:
lrmoore earned 350 total points
ID: 12281371
At the same site, there is an option for User Specified Custom Port Probe.
Use this to specify the port range..up to 65535..

0
 
LVL 2

Author Comment

by:meade470
ID: 12281623
Oh . . . duh.  I guess it helps when you look at the page.  :)

Quick question, if you don't mind:  Wouldn't you consider it normal for a PIX to respond in "stealth" mode rather than "closed."  Also, would you consider "stealth" mode to be the better choice of the two?

Thanks!!!!
mEadEman
0
 
LVL 79

Expert Comment

by:lrmoore
ID: 12281852
Been there, done that already..
http://www.experts-exchange.com/Security/Firewalls/Q_20589406.html

Yes, I would say that "stealth" is better than "closed"

0

Featured Post

Efficient way to get backups off site to Azure

This user guide provides instructions on how to deploy and configure both a StoneFly Scale Out NAS Enterprise Cloud Drive virtual machine and Veeam Cloud Connect in the Microsoft Azure Cloud.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This article assumes you have at least one Cisco ASA or PIX configured with working internet and a non-dynamic, public, address on the outside interface. If you need instructions on how to enable your device for internet, or basic configuration info…
This article will cover setting up redundant ISPs for outbound connectivity on an ASA 5510 (although the same should work on the 5520s and up as well).  It’s important to note that this covers outbound connectivity only.  The ASA does not have built…
Both in life and business – not all partnerships are created equal. As the demand for cloud services increases, so do the number of self-proclaimed cloud partners. Asking the right questions up front in the partnership, will enable both parties …
As a trusted technology advisor to your customers you are likely getting the daily question of, ‘should I put this in the cloud?’ As customer demands for cloud services increases, companies will see a shift from traditional buying patterns to new…

910 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

23 Experts available now in Live!

Get 1:1 Help Now