cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1185
Views
10
Helpful
7
Replies

Cisco 2801 security issue - open ports

Alex_Kitaichik
Level 1
Level 1

Hello all,

I have some strange issue with my cisco 2801:

The router has 2 interfaces with legal PA addresses - one to ISP and one to my LAN.

There is no nat configuration on this router.

When I run nmap scanning on IP address that configured on LAN interface - I can see 2 open ports - 1720 and 5060.

The router IOS version is 12.3(14)T2 .

Any guess?

Alexander

1 Accepted Solution

Accepted Solutions
7 Replies 7

Peter Paluch
Cisco Employee
Cisco Employee

Hi Alex,

It would be helpful to see your configuration. However, the 5060 is the SIP port, and 1720 is used by H.323. Are any of these services running on your device?

Best regards,

Peter

I can't send you a full configuration because of security policy of my company but I can to post a relevant parts of configuration.

I want to be clear, there is no NAT configured on router and I scanned the LAN interface - so I guess it is impossible that any of this ports will be opened. Anyway I don't have any of these services runs on router and no in LAN.

Alexander

Hi,

to see open ports on your router you can do both commands:

-sh ip sockets  (  for non TCP ports)

- sh  tcp brief all

Regards.

Alain

Don't forget to rate helpful posts.

Hi Alain,

I've been searching for a while for these commands. Good find! +5

Sent from Cisco Technical Support iPhone App

Acctually I can see next situation on my router:

Router#sh tcp brief all

TCB       Local Address           Foreign Address        (state)

6473E0DC  *.1720                  *.*                    LISTEN

64D9A5E4  *.5060                  *.*                    LISTEN

64BFB57C  *.1723                  *.*                    LISTEN

How can I know what service opens these ports? How can I manage/change this situation?

Alexander

Hi,

https://supportforums.cisco.com/docs/DOC-3031

Regards.

Alain

Don't forget to rate helpful posts.

Alain,

Nice one!

Best regards,

Peter

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card