Re: how to verify it is a stateful firewall.

From: .Saphyr (saNphOyr_at_inSfomPanAiak.Mch)
Date: 08/19/03


Date: Tue, 19 Aug 2003 11:53:25 GMT


> I just found something with nmap. Is half open, option -sS with nmap
> actually try to generate an unstateful connection? What other example I
> can use?
>
> Thanks
> sam

Lock everything, allow outgoing connection from your browser and see if
your fw locks the returning data. If the page gets displayed, you have
a statefull firewall. Otherwise, you would have to add a rule like

"allow from any 80 to myself any"

.antoine


Quantcast