cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
463
Views
0
Helpful
4
Replies

Prevent Stealth Scans

cplatt01
Level 1
Level 1

What is the best defense against stealth scans of the network? I know this is a vague and open question.

How do you prevent when signature detects a single TCP packet with none of the control bits, i.e. SYN, FIN, ACK, PSH, URG or RST flags set being sent to a specific host.

4 Replies 4

David White
Cisco Employee
Cisco Employee

Hi,

I'm not sure we are totally following your question. Are you asking specificly to the PIX/ASA/FWSM or a more generic question relating to IPS/IDS?

Sincerely,

David.

More for the PIX.

The Pix will drop null packets. Any firewall should.

The PIX will silently drop these packets (ie: no syslog generated). In 7.x, many of these will get counted in the "show asp drop" output, but again, no syslog generated.

David.

Review Cisco Networking products for a $25 gift card