Re: Port scan from grc.com fails 1st time passes the 2nd?

From: Duane Arnold (notme_at_notme.com)
Date: 03/11/05


Date: Fri, 11 Mar 2005 17:46:02 GMT


"Paul H" <nospam@nospam.com> wrote in
news:13jYd.3226$7r6.1045@newsfe5-gui.ntli.net:

> We have a NAT router with SPI protecting our small LAN.
>
> When I go to http://grc.com and run the shields up scan on common
> ports, it shows the following ports as open; 21, 23 and 80. If I run
> the scan again afew seconds later all ports show a stealthed. If I
> leave it for a few minutes and run the scan again the ports are open
> again.
>
> OK so the firewall is "reacting" to an intrusion attempt, but wouldn't
> it be better to be closed or stealthed the FIRST time an intrusion was
> attempted? Can anyone comment on this routers behaviour? I have never
> seen a router do this before, is it a potential risk, or is it being
> "smart"?
>
> Thanks
>
> Paul
>
>

What router are you talking about? Stealth means nothing to the router. The
machine or machines are *stealth* because they are behind the router. The
ports on the router are *closed* by default. The only way they are open is
due do a machine running a program and the program is making a solicitation
to a remote IP causing the port(s) to *ONLY* (especially true with SPI) be
open to that traffic. Or you have configured the router by doing port
forwarding to open and (leave open) to the public Internet specified
inbound ports for a specific program to listen on those port(s).

You should seek out some other testing sites and not depend solely on the
Gibson site to tell you what's happening with the ports.

And if the NAT router is like most NAT routers, then it's likely a NAT (no
true firewall) router with FW like features.

Duane :)



Relevant Pages

  • Re: Others seeing my pc.
    ... It does the same as any other router would. ... >> as stealth except for 9001 and 9030 which are open for my Tor node. ... >> using those 2 ports. ...
    (alt.privacy)
  • Re: Others seeing my pc.
    ... It does the same as any other router would. ... > thorough check at "Shields Up" at www.grc.com shows all of my ports ... I was never a big fan of GRC, or goofy buzzwords like "stealth". ... Outside of a dog, a book is a man's best friend. ...
    (alt.privacy)
  • Re: Wanting to hide :113
    ... If only the ports are stealthed, the router could respond in other ways to ... router to report that the system is not present if turned off. ... If the router is completely stealth - drops all communication and doesn't ...
    (comp.security.firewalls)
  • Re: Port scan from grc.com fails 1st time passes the 2nd?
    ... >> We have a NAT router with SPI protecting our small LAN. ... >> the scan again afew seconds later all ports show a stealthed. ... Stealth means nothing to the router. ...
    (comp.security.firewalls)
  • Re: 2 pc network - cant see host files from pc 2 on pc 1
    ... Assuming that you have firewall protection via your internet router try ... workgroup because it will be needed for the network to work correctly. ... see if you can access TCP ports 139 and 445 on computer one of which at ... permissions. ...
    (microsoft.public.windowsxp.security_admin)

Quantcast