Re: [Security-Discuss] Question about DSL modem/router/firewall vs. firewall scans at scan.sygate.com
Michael Scherer <[email protected]> Fri, 17 Mar 2006 23:29:57 +0100
| Newsgroups | gmane.linux.mandrake.security.general |
|---|---|
| Message-ID | <[email protected]> |
Le vendredi 17 mars 2006 à 14:06 -0600, AAW a écrit : > We recently changed from dial-up to DSL (PPPoe) and added a modem/router > (Zoom X5) with built-in firewall. First thing I did was to point my > browser to scan.sygate.com to check the firewall. I'm used to seeing all > ports come back as blocked, but that isn't what I got this time. > > The TCP scan (http://scan.sygate.com/pretcpscan.html) shows ports 260 and > 557 open. The UDP scan (http://scan.sygate.com/preudpscan.html) says that > most scanned ports are closed (rejecting packets) rather than blocked > (silently dropping packets) and several are open, including 53 (DNS), 138 > (NetBIOS), 1900 (UPnP). The Quick Scan and Stealth Scan show a number of > ports that are closed rather than blocked. My opinion is that closed port are more rfc compliant, but that is a personal preference :) > Is this normal for a router with a firewall? I thought they were supposed > to be more secure than software-based firewalls. Well, even hardware firewall ( or appliance ) run software, even if they have been designed to do only that. I would say this is not normal. You should hovever try with another scan, ask to a friend to run nmap on your ip address. Maybe the ip packet do not even reach the modem router, if the provider block them before. -- Michael Scherer ____________________________________________________ Want to buy your Pack or Services from Mandriva? Go to http://store.mandriva.com Join the Club : http://www.mandrivaclub.com ____________________________________________________