- Sep 20, 2003
- 9,599
- 2
- 0
I just ran a quick scan with nmap on my work firewall for the heck of it and all of the UDP ports came up as open|filtered. Is this normal and are they really stealthed?
I just ran a quick scan with nmap on my work firewall for the heck of it and all of the UDP ports came up as open|filtered. Is this normal and are they really stealthed?
Are you scanning from inside our outside, that would make a big diff.
Originally posted by: Nothingman
What kind of firewall is it? I remember the instructor at SANS this year talking about older versions of some firewalls that would basically open every port to do their proxy thing, so a port scan would show everything open and the firewall company was just like "yea, so?". I don't think that's true any more, but you never know if you're running something like a Checkpoint.
I'm thinking that coming up as open|filtered might be standard speech in nmap for stealthed as I was scanning a friends's router yesterday and it had the same result.
