Forum Discussion
ports are showing open on online scanning tool
- Jan 20, 2025
Hello Team,
We have raised F5 case for this issue and F5 Internal team have found few logs and few TCP half-open (SYN cookie) vector which might be causing this issue which are related to AFM module. To isolate the issue internal has suggested to upgrade the tenant to the latest 17.1.1.4 (stability release) and F5OS to at least 1.5.2. and After upgrading the tenant to version 17.1.1.4 and F5OS to version 1.5.2, the issue has been resolved.
Paulius, thanks for your reply. As you mentioned, in our scenario, one condition is met: the self IP is configured as a virtual server. To resolve this, can we change the self IP during downtime?
Pooja_Varekar208 This depends on your overall configuration. At face value, you should be able to create a new virtual server (VS) the exact same way but with a different virtual IP to test and then during a maintenance window you can remove the old VS and point everything to the new VS. For future reference, you should refrain from using the self or floating IPs as a VS because it can cause some issue, your security scan being one of them.
- Pooja_Varekar208Dec 24, 2024
Altocumulus
Paulius, thanks for providing such a helpful solution!
- LiefZimmermanJan 02, 2025
Admin
It is helpful to others in the community if you can choose “mark as solution” on the reply.
thanks!- Pooja_Varekar208Jan 02, 2025
Altocumulus
As mentioned by Paulius, one condition in our scenario is that the self-IP is configured as a virtual server. We made the necessary changes during the maintenance window, but it is still not working, and the ports are still showing as open on online port checker tool
- Pooja_Varekar208Dec 27, 2024
Altocumulus
For auditing purposes, we have transitioned our F5 box to a VM environment. This VM was previously utilized before we adopted the F5 hardware appliance and is running version 11.x. When performing online port scans, the system displays only the specific ports that are configured to be open.
The configuration of both devices—the previous box (iSeries-11.x) and the current box (Rseries-Tenant-17.1.0.1)—is identical.
On the old box, the self IP was configured as a virtual server, yet it displayed only the specific ports that were configured to be open. However, on the new box, all ports appear to be open when scanned.
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com