<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Prevent Stealth Scans in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/prevent-stealth-scans/m-p/771963#M1008536</link>
    <description>&lt;P&gt;What is the best defense against stealth scans of the network?  I know this is a vague and open question.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How do you prevent when signature detects a single TCP packet with none of the control bits, i.e. SYN, FIN, ACK, PSH, URG or RST flags set being sent to a specific host.&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 09:54:41 GMT</pubDate>
    <dc:creator>cplatt01</dc:creator>
    <dc:date>2019-03-11T09:54:41Z</dc:date>
    <item>
      <title>Prevent Stealth Scans</title>
      <link>https://community.cisco.com/t5/network-security/prevent-stealth-scans/m-p/771963#M1008536</link>
      <description>&lt;P&gt;What is the best defense against stealth scans of the network?  I know this is a vague and open question.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How do you prevent when signature detects a single TCP packet with none of the control bits, i.e. SYN, FIN, ACK, PSH, URG or RST flags set being sent to a specific host.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 09:54:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/prevent-stealth-scans/m-p/771963#M1008536</guid>
      <dc:creator>cplatt01</dc:creator>
      <dc:date>2019-03-11T09:54:41Z</dc:date>
    </item>
    <item>
      <title>Re: Prevent Stealth Scans</title>
      <link>https://community.cisco.com/t5/network-security/prevent-stealth-scans/m-p/771964#M1008537</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm not sure we are totally following your question. Are you asking specificly to the PIX/ASA/FWSM or a more generic question relating to IPS/IDS?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sincerely,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;David.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 02 Apr 2007 15:55:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/prevent-stealth-scans/m-p/771964#M1008537</guid>
      <dc:creator>David White</dc:creator>
      <dc:date>2007-04-02T15:55:58Z</dc:date>
    </item>
    <item>
      <title>Re: Prevent Stealth Scans</title>
      <link>https://community.cisco.com/t5/network-security/prevent-stealth-scans/m-p/771965#M1008538</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;More for the PIX.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 02 Apr 2007 15:57:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/prevent-stealth-scans/m-p/771965#M1008538</guid>
      <dc:creator>cplatt01</dc:creator>
      <dc:date>2007-04-02T15:57:24Z</dc:date>
    </item>
    <item>
      <title>Re: Prevent Stealth Scans</title>
      <link>https://community.cisco.com/t5/network-security/prevent-stealth-scans/m-p/771966#M1008541</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The Pix will drop null packets. Any firewall should.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 02 Apr 2007 16:12:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/prevent-stealth-scans/m-p/771966#M1008541</guid>
      <dc:creator>mhellman</dc:creator>
      <dc:date>2007-04-02T16:12:45Z</dc:date>
    </item>
    <item>
      <title>Re: Prevent Stealth Scans</title>
      <link>https://community.cisco.com/t5/network-security/prevent-stealth-scans/m-p/771967#M1008542</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The PIX will silently drop these packets (ie: no syslog generated).   In 7.x, many of these will get counted in the "show asp drop" output, but again, no syslog generated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;David.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 02 Apr 2007 16:12:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/prevent-stealth-scans/m-p/771967#M1008542</guid>
      <dc:creator>David White</dc:creator>
      <dc:date>2007-04-02T16:12:49Z</dc:date>
    </item>
  </channel>
</rss>

