Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

How Do I Check What Traffic Is Using A Certain Port

I'm not a network guy so please forgive me if this is a simple answer.

We have to be PCI compliant. We passed the network scan last year, and failed this year with this report:

TCP 2323 - Unencrypted Communication Channel Accessibility. 

Description: The service running on this port appears to make use of a plaintext (unencrypted) communication channel. The PCI DSS forbids the use of such insecure services/protocols. Unencrypted communication channels are vulnerable to the disclosure and/or modification of any data transiting through them (including usernames and passwords), and as such the confidentially and integrity of the data in transit cannot be ensured with any level of certainty.

Remediation: Transition to using more secure alternatives such as SSH instead of Telnet and SFTP in favor of FTP, or consider wrapping less secure services within more secure technologies by utilizing the benefits offered by VPN, SSL/TLS, or IPSec for example. Also, limit access to management protocols/services to specific IP addresses (usually accomplished via a "whitelist") whenever possible.

How do I find what's using this port? I'm not a network guru, just a volunteer for our organization. Thanks



This thread was automatically locked due to age.
  • In 'Logging & Reporting >> Network Usage', you can look up clients and servers using this port on the 'Bandwidth Usage' tab.

    Cheers - Bob

    PS What does the organization do and where is it located?

    Cheers - Bob

  • Thanks for directing me on the right path Bob. However I'm still not able to find what I'm looking for. I'm looking at the "Top Services" tab and looking in the past few months when the scan failed and not seeing anything under specifically mentioning port 2323. Then when I switch to "Top clients by service" and search for port 2323, nothing shows up.

    Am I missing something?

    Also, we are a church in Texas. Thanks!

  • Did you try for both "TCP 2323" and "UDP 2323" there?  If you can't find anything, maybe it's because the access was long enough ago that your configuration has dropped the record of it => check 'Report Settings'.

    Cheers - Bob