Prevent Public Network Devices From Scanning IAM Ports

|
  • 157
  • 5

Issue Description

The IAM is deployed in the routing mode. The external network access device needs to scan the IAM port.

Handling Process

1. 12.0.14 and newer versions support closing the port in [System]-[Network]-[Advanced]-[Open Ports On WAN Interface].

2. Other versions can implement this function through DNAT rules. For example, the public network device is prohibited from scanning the TCP port 81-100. The request to access the port number 81-100 of the IAM WAN port can be mapped to a non-existing address on the intranet. For example, here [Mapped Port] – [Specified IP] is filled in 12.23.34.56.


Solution

By translating the scan request to access the IAM to a port that scans for non-existent IP.
Faisal Posted 12 Aug 2020 09:36
  
Thank you very much for the information ...
Faisal Posted 31 Oct 2020 09:44
  
Nice article ...
Faisal Posted 04 Dec 2020 08:34
  
Great Info
Faisal Posted 11 Mar 2021 09:52
  
Very informative …
Faisal Posted 27 May 2021 14:17
  
Nice guidance ...

I want to write a case
Doc ID: 2646
Author: Newbie280530
Updated: 2019-12-24 11:47
Version: