Discussion in 'other firewalls' started by RadarSP, Apr 2, 2007.

  RadarSP

    RadarSP

    Feb 6, 2007
    Which is the most sensible firewall to detect ports scan, like nmap?
    Im talking about xmas, null, fin or syn snan, without ping....
    Most firewalls block this scans but dont display alerts.
  sukarof

    sukarof

    Jun 22, 2004
    Stockholm Sweden
    Take a look at Look´n´Stop. Not that it says much, but I dont understand half of the blocks it makes in the log :D
  KDNeese

    KDNeese

    Dec 16, 2005
    I've been told that port scanners are not really a good idea, and can actually make your system vulnerable to attack. That may or may not be true, but the logic in some of the articles I've read makes sense. What I have done is use Kerio firewall with the NIPS function, which uses Snort rules, and keep the NIPS updated with the latest Snort rules. The NIPS (Snort) rules are signature based, and can detect specific port scans (such as XMAS) and behavioral anomolies (various types of spoofing, etc). Snort is a good IDS, and can be incorporated into the other security features of the firewall. I use the NIPS function along with tight rules created with the packet filter module. I think this makes for a very good and secure setup.
