Blocking OS detection

Unanswered Question
Sep 7th, 2007
User Badges:

Hello everyone,


Is there a way to protect against operating system detection using Cisco PIX similar to "mangle" feature of IPTables that allows modification of response packets from the server behind the firewall to imitate some other operating system?


If not "mangle", are there any other ways of blocking against this detection type?


Any help would be greatly appreciated.


Thanks.


Clone

  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
Loading.
cpembleton Mon, 09/10/2007 - 18:49
User Badges:
  • Silver, 250 points or more

What version code are your running? 6.X or 7.X?


6.X has some application inspection (fixup) that masks banner info but very limited.


7.X has application inspection for some well known ports. You can use regular expressions to match specific traffic and mask out there response.


7.x Application inspection:

http://www.cisco.com/en/US/customer/docs/security/asa/asa72/configuration/guide/inspect.html


Thanks,

Chad

Actions

This Discussion