Re: [Security-Discuss] Question about DSL modem/router/firewall vs. firewall scans at scan.sygate.com

Michael Scherer <[email protected]> Fri, 17 Mar 2006 23:29:57 +0100
Newsgroups gmane.linux.mandrake.security.general
Message-ID <[email protected]>
Le vendredi 17 mars 2006 à 14:06 -0600, AAW a écrit :
> We recently changed from dial-up to DSL (PPPoe) and added a modem/router 
> (Zoom X5) with built-in firewall. First thing I did was to point my 
> browser to scan.sygate.com to check the firewall. I'm used to seeing all 
> ports come back as blocked, but that isn't what I got this time.
> 
> The TCP scan (http://scan.sygate.com/pretcpscan.html) shows ports 260 and 
> 557 open. The UDP scan (http://scan.sygate.com/preudpscan.html) says that 
> most scanned ports are closed (rejecting packets) rather than blocked 
> (silently dropping packets) and several are open, including 53 (DNS), 138 
> (NetBIOS), 1900 (UPnP). The Quick Scan and Stealth Scan show a number of 
> ports that are closed rather than blocked. 

My opinion is that closed port are more rfc compliant, but that is a
personal preference :)


>  Is this normal for a router with a firewall? I thought they were supposed 
> to be more secure than software-based firewalls.

Well, even hardware firewall ( or appliance ) run software, even if they
have been designed to do only that.

I would say this is not normal. 
You should hovever try with another scan, ask to a friend to run nmap on
your ip address. 
Maybe the ip packet do not even reach the modem router, if the provider
block them before.

-- 
Michael Scherer

____________________________________________________
Want to buy your Pack or Services from Mandriva? 
Go to http://store.mandriva.com
Join the Club : http://www.mandrivaclub.com
____________________________________________________