Change The Port Status To Filtered

|
  • 177
  • 5

Issue Description

The public network accesses the NGAF port through Local ACL deny, but the nmap scan finds that the port is closed, but the client wants the port status to be filtered.

Handling Process

Go to Policies > NAT Check that the DNAT configuration does not use these ports.

Root Cause

NGAF has a reply RST package to the scanner,Then the scanner will think that the port status is filtered.

Solution

After modifying the following configuration, the NGAF will not send TCP Reset message to reject request.
Faisal Posted 13 Aug 2020 07:44
  
Thank you very much for the information ...
Faisal Posted 30 Oct 2020 11:23
  
Nice article ...
Faisal Posted 09 Dec 2020 09:04
  
Great info ...
Faisal Posted 12 Mar 2021 07:27
  
Very informative …
Faisal Posted 28 May 2021 06:57
  
Nice guidance ...

I want to write a case
Doc ID: 2471
Author: CTI Jimy
Updated: 2019-12-24 11:06
Version: