This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

How to make IM/P2P protocols invisible for network scanners

I like to switch off IM/P2P but an external network scan claims some ports left opened. I uses an active/active cluster with Snort on and "anti-port" scanning on . The scan was performed with IM/P2P all settings switched off and also an "any" skiplist with the same results:

Starting Nmap 4.76 ( Nmap - Free Security Scanner For Network Exploration & Security Audits. ) at 2009-01-07 01:23 Westeuropäische Normalzeit
Initiating Parallel DNS resolution of 1 host. at 01:23
Completed Parallel DNS resolution of 1 host. at 01:23, 0.05s elapsed
Initiating SYN Stealth Scan at 01:23
Scanning 82.98.***.***[1000 ports]
SYN Stealth Scan Timing: About 15.00% done; ETC: 01:27 (0:02:54 remaining)
Discovered open port 1863/tcp on 82.98.***.***
Discovered open port 5190/tcp on 82.98.***.***
Completed SYN Stealth Scan at 01:24, 46.69s elapsed (1000 total ports)
Host 82.98.***.*** appears to be up ... good.


This thread was automatically locked due to age.
Parents
  • I'd guess that your packet filter rules do allow that traffic.  The IM/P2P control in the Astaro is a specialized use of the flow-classification tool used in the Intrusion Protection System; it is a way of restricting specific IM/P2P traffic if the packet filter rules allow it in.  It is not a proxy like HTTP for web traffic or SMTP for email.

    Cheers - Bob
     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
Reply
  • I'd guess that your packet filter rules do allow that traffic.  The IM/P2P control in the Astaro is a specialized use of the flow-classification tool used in the Intrusion Protection System; it is a way of restricting specific IM/P2P traffic if the packet filter rules allow it in.  It is not a proxy like HTTP for web traffic or SMTP for email.

    Cheers - Bob
     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
Children
No Data