Blocking OS detection

Unanswered Question
Sep 7th, 2007

Hello everyone,

Is there a way to protect against operating system detection using Cisco PIX similar to "mangle" feature of IPTables that allows modification of response packets from the server behind the firewall to imitate some other operating system?

If not "mangle", are there any other ways of blocking against this detection type?

Any help would be greatly appreciated.

Thanks.

Clone

I have this problem too.
0 votes
  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
Loading.
cpembleton Mon, 09/10/2007 - 18:49

What version code are your running? 6.X or 7.X?

6.X has some application inspection (fixup) that masks banner info but very limited.

7.X has application inspection for some well known ports. You can use regular expressions to match specific traffic and mask out there response.

7.x Application inspection:

http://www.cisco.com/en/US/customer/docs/security/asa/asa72/configuration/guide/inspect.html

Thanks,

Chad

Actions

This Discussion