ASA Open Port Hardening

Unanswered Question
Nov 9th, 2008

Hi, i have a new ASA appliance without any configuration except interface configuration, which i have configure an IP to perform port scan using port scanner. The port scan result showed the new ASA 5540 appliance default is opened with port 110 and 25, how can i disable or close these 2 open ports ? Pls. advise.

I have this problem too.
0 votes
  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
Loading.
husycisco Sun, 11/09/2008 - 13:08

Hello Beng,

No, ASA does not have these ports open by default. It may be another host (most probably an exchange server) that port scanner scanned, or security-levels mis-configured, or an acl exist to permit this specific traffic.

Regards

benghock Mon, 11/10/2008 - 05:51

Hi, thanks for the replying, for your information, this ASA is a new box which is not connected to any network, i just configured one of the interface with IP and use my scanner tool to scan the interface, and the scanner result showed that the ports 110 and 25 are opened. Pls. advise if possible. Thanks

husycisco Mon, 11/10/2008 - 14:06

Beng,

I cleared configuration and built basic configuration on my test firewall, and launched portscan using nessus, and these ports were not open. Can you post your whole config?

Regards

Actions

This Discussion