cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
840
Views
5
Helpful
7
Replies

Nmap UDP Port Sweep

sagittarius
Level 1
Level 1

Hi,

We are getting some events on IPS for Nmap UDP Port Sweep (Signature - 4003). Attacker shows an external address, what can I do for this alert, what actions can I take?

7 Replies 7

mhellman
Level 7
Level 7

Generally, even if it's legitimate it's not something to worry about. More than likely though, it's just return traffic. Please provide the source and destination ports.

Destination Port # changes from udp/356,357,358,361,367,359,500 however the attacker port remains the same (500 or 137)

udp 500 and 137 are both well known udp ports (isakmp and netbios-ns), so there's a good chance this is udp reply traffic to a know port. Are the source IP addresses internal? Are the destination IP addresses internal?

yes source IP is internal and destination is external.

I've confused myself. to clarify:

SOURCE IP:PORT = :356,357,500,etc

DESTINATION IP:PORT = :137,500

Is that right?

No,

Source Port :: 137,500

Destination Port: : 356,357,500

I guess I'm missing something. attacker = source ip unless "swap attacker victim" is selected, which it isn't by default for this sig.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card