Forum Discussion
mframpton_60606
Nimbostratus
Oct 23, 2008Unused ports respond to port scan
We're in the process of nailing down open ports on our network. We've found that if we do a port scan on an LTM VIP with a defined port, all the unused ports will responded with an ACK then Reset, which unfortunately shows up in the scanning software as an open port. Anyone know of a way to tell the LTM to not give an ACK?
TIA!
- hoolio
Cirrostratus
I'm pretty sure TCP RFCs dictate that LTM or any host send an ACK of the previous packet and a RST if the port isn't in a listening state. I'm not sure if this is configurable within the internal database. I didn't see any keys which looked related in a quick search of the database (b db list|less -i). - hoolio
Cirrostratus
I'd suggest configuring this in an upstream fiirewall.
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects