Re: Firewall Stealth Mode?



a_monk wrote:
As I understand, when the external interface of a firewall is being
scanned by "nessus", "nmap", or/and other scanning tools, one should
not be able to "see" any opening services, EVEN though services, e.g.,
web, mail, ftp, are published their services using the IP address of
the external interface of the firewall.

Recently, a security consultant explained to me that the stealth mode
of a firewall is meant just that the firewall does not respond to ICMP
only, therefore when the firewall is scanned, the services published
using that IP address are still visible/reported.

Both your understanding, the explaination and the "stealth mode" itself
are nonsense.
.



Relevant Pages

  • Re: Possibly Off Topic: Firewalls
    ... "Stealth Mode" disables the computer's responses to incoming traffic it is ... Firewall that says not only "Did I start this conversation," but also "Was I ... John McGhie wrote: ... John McGhie, Microsoft MVP (Word, Mac Word), Consultant Technical Writer, ...
    (microsoft.public.mac.office.word)
  • Re: Possibly Off Topic: Firewalls
    ... John McGhie wrote: ... "Stealth Mode" disables the computer's responses to incoming traffic it is ... Firewall that says not only "Did I start this conversation," but also "Was I ... John McGhie, Microsoft MVP (Word, Mac Word), Consultant Technical Writer, ...
    (microsoft.public.mac.office.word)
  • Re: Firewall Stealth Mode?
    ... web, mail, ftp, are published their services using the IP address of ... the external interface of the firewall. ... of a firewall is meant just that the firewall does not respond to ICMP ... the explaination and the "stealth mode" itself ...
    (comp.security.firewalls)
  • Re: Attacked
    ... pooter is there, or so I'm told. ... how do you put them into stealth mode? ... Your firewall should be set to do it do it Pam. ...
    (uk.people.silversurfers)
  • Re: Firewall Stealth Mode?
    ... Jason wrote: ... not be able to "see" any opening services, EVEN though services, e.g., ... web, mail, ftp, are published their services using the IP address of ... of a firewall is meant just that the firewall does not respond to ICMP ...
    (comp.security.firewalls)