<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Pix gives the impression that a port is open when it is not in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/pix-gives-the-impression-that-a-port-is-open-when-it-is-not/m-p/1201934#M859781</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Andrew,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you very much for clearing this!...just for general knowledge how can I change that TCP settings??&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best Regards,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 15 May 2009 14:45:20 GMT</pubDate>
    <dc:creator>alfonso.cornejo</dc:creator>
    <dc:date>2009-05-15T14:45:20Z</dc:date>
    <item>
      <title>Pix gives the impression that a port is open when it is not</title>
      <link>https://community.cisco.com/t5/network-security/pix-gives-the-impression-that-a-port-is-open-when-it-is-not/m-p/1201932#M859779</link>
      <description>&lt;P&gt;Hi to all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have this scenario, I have a pix firewall and in one DMZ i have my servers, i have allowed only the https access to one of them from the outside interface but if i make a telnet to the server for any port the firewall gives the impression that it is open.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For example if from an MS-DOS command line i try a telnet to the server to the port 1200 wich is not allowed by the firewall and is also closed in the server the MS-DOS window gets "black" wich means that the port is open but as soon as i press a key the MS-DOS window gets closed so it means that the connection was not stablished wich is correct but it gave the impresion that it was stablished.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you have any ideas about what could be causing this?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 15:32:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-gives-the-impression-that-a-port-is-open-when-it-is-not/m-p/1201932#M859779</guid>
      <dc:creator>alfonso.cornejo</dc:creator>
      <dc:date>2019-03-11T15:32:37Z</dc:date>
    </item>
    <item>
      <title>Re: Pix gives the impression that a port is open when it is not</title>
      <link>https://community.cisco.com/t5/network-security/pix-gives-the-impression-that-a-port-is-open-when-it-is-not/m-p/1201933#M859780</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This is normal - the pix will just "drop" the packets silently, without sending a "reset" to the remote end indicating there was any kind of connection - basically the firewall is giving the impression of a blackhole.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you change the TCP settings, to send a reset back - you are announcing there is something there, not allways the best approach.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 15 May 2009 08:54:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-gives-the-impression-that-a-port-is-open-when-it-is-not/m-p/1201933#M859780</guid>
      <dc:creator>andrew.prince</dc:creator>
      <dc:date>2009-05-15T08:54:56Z</dc:date>
    </item>
    <item>
      <title>Re: Pix gives the impression that a port is open when it is not</title>
      <link>https://community.cisco.com/t5/network-security/pix-gives-the-impression-that-a-port-is-open-when-it-is-not/m-p/1201934#M859781</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Andrew,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you very much for clearing this!...just for general knowledge how can I change that TCP settings??&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best Regards,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 15 May 2009 14:45:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-gives-the-impression-that-a-port-is-open-when-it-is-not/m-p/1201934#M859781</guid>
      <dc:creator>alfonso.cornejo</dc:creator>
      <dc:date>2009-05-15T14:45:20Z</dc:date>
    </item>
    <item>
      <title>Re: Pix gives the impression that a port is open when it is not</title>
      <link>https://community.cisco.com/t5/network-security/pix-gives-the-impression-that-a-port-is-open-when-it-is-not/m-p/1201935#M859782</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sure no - OK the config you need is:-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;service resetinbound&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;" Causes the security appliance to send TCP resets for all TCP sessions that arrive at the interface, are attempting to transit the security appliance, and are denied by the security appliance based on access lists. When this option is not selected, the security appliance silently discards the packets of all such sessions"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;service resetoutside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;" Causes the security appliance to send TCP resets for all TCP sessions that arrive at the least secure interface, terminate at the least secure interface, and are denied by the security appliance based on access lists. When this option is not selected, the security appliance silently discards the packets of all such sessions"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&amp;gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 15 May 2009 14:49:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-gives-the-impression-that-a-port-is-open-when-it-is-not/m-p/1201935#M859782</guid>
      <dc:creator>andrew.prince</dc:creator>
      <dc:date>2009-05-15T14:49:46Z</dc:date>
    </item>
    <item>
      <title>Re: Pix gives the impression that a port is open when it is not</title>
      <link>https://community.cisco.com/t5/network-security/pix-gives-the-impression-that-a-port-is-open-when-it-is-not/m-p/1201936#M859783</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank's alot Andrew!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 15 May 2009 15:02:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-gives-the-impression-that-a-port-is-open-when-it-is-not/m-p/1201936#M859783</guid>
      <dc:creator>alfonso.cornejo</dc:creator>
      <dc:date>2009-05-15T15:02:25Z</dc:date>
    </item>
    <item>
      <title>Re: Pix gives the impression that a port is open when it is not</title>
      <link>https://community.cisco.com/t5/network-security/pix-gives-the-impression-that-a-port-is-open-when-it-is-not/m-p/1201937#M859784</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;np - glad to help.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 15 May 2009 15:05:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-gives-the-impression-that-a-port-is-open-when-it-is-not/m-p/1201937#M859784</guid>
      <dc:creator>andrew.prince</dc:creator>
      <dc:date>2009-05-15T15:05:58Z</dc:date>
    </item>
    <item>
      <title>Re: Pix gives the impression that a port is open when it is not</title>
      <link>https://community.cisco.com/t5/network-security/pix-gives-the-impression-that-a-port-is-open-when-it-is-not/m-p/1201938#M859785</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Andrew,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you know a cisco document that confirm this??&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The security department is asking me for an evidence from cisco.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance for your help.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best Regards,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 01 Jun 2009 18:59:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-gives-the-impression-that-a-port-is-open-when-it-is-not/m-p/1201938#M859785</guid>
      <dc:creator>alfonso.cornejo</dc:creator>
      <dc:date>2009-06-01T18:59:17Z</dc:date>
    </item>
    <item>
      <title>Re: Pix gives the impression that a port is open when it is not</title>
      <link>https://community.cisco.com/t5/network-security/pix-gives-the-impression-that-a-port-is-open-when-it-is-not/m-p/1201939#M859786</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Alfonso,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What device (PIX/ASA) do you have and what version of software are you running (6.x,7.x or 8.x) ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 01 Jun 2009 20:33:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-gives-the-impression-that-a-port-is-open-when-it-is-not/m-p/1201939#M859786</guid>
      <dc:creator>andrew.prince</dc:creator>
      <dc:date>2009-06-01T20:33:24Z</dc:date>
    </item>
    <item>
      <title>Re: Pix gives the impression that a port is open when it is not</title>
      <link>https://community.cisco.com/t5/network-security/pix-gives-the-impression-that-a-port-is-open-when-it-is-not/m-p/1201940#M859787</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Andrew,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PIX 7.2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 01 Jun 2009 21:13:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-gives-the-impression-that-a-port-is-open-when-it-is-not/m-p/1201940#M859787</guid>
      <dc:creator>alfonso.cornejo</dc:creator>
      <dc:date>2009-06-01T21:13:28Z</dc:date>
    </item>
    <item>
      <title>Re: Pix gives the impression that a port is open when it is not</title>
      <link>https://community.cisco.com/t5/network-security/pix-gives-the-impression-that-a-port-is-open-when-it-is-not/m-p/1201941#M859788</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Alfonso,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;See the below URL for the version of PIX IOS you are using:-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/docs/security/asa/asa72/command/reference/s1_72.html#wp1290652" target="_blank"&gt;http://www.cisco.com/en/US/docs/security/asa/asa72/command/reference/s1_72.html#wp1290652&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&amp;gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 02 Jun 2009 14:30:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-gives-the-impression-that-a-port-is-open-when-it-is-not/m-p/1201941#M859788</guid>
      <dc:creator>andrew.prince</dc:creator>
      <dc:date>2009-06-02T14:30:17Z</dc:date>
    </item>
    <item>
      <title>Re: Pix gives the impression that a port is open when it is not</title>
      <link>https://community.cisco.com/t5/network-security/pix-gives-the-impression-that-a-port-is-open-when-it-is-not/m-p/1201942#M859789</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you very much again Andrew!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 03 Jun 2009 02:03:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-gives-the-impression-that-a-port-is-open-when-it-is-not/m-p/1201942#M859789</guid>
      <dc:creator>alfonso.cornejo</dc:creator>
      <dc:date>2009-06-03T02:03:43Z</dc:date>
    </item>
    <item>
      <title>Re: Pix gives the impression that a port is open when it is not</title>
      <link>https://community.cisco.com/t5/network-security/pix-gives-the-impression-that-a-port-is-open-when-it-is-not/m-p/1201943#M859790</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;np - glad to help.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 03 Jun 2009 07:38:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-gives-the-impression-that-a-port-is-open-when-it-is-not/m-p/1201943#M859790</guid>
      <dc:creator>andrew.prince</dc:creator>
      <dc:date>2009-06-03T07:38:07Z</dc:date>
    </item>
    <item>
      <title>Re: Pix gives the impression that a port is open when it is not</title>
      <link>https://community.cisco.com/t5/network-security/pix-gives-the-impression-that-a-port-is-open-when-it-is-not/m-p/1201944#M859791</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Andrew,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Just today i had the opportunity to try the commands service resetinbound and service resetoutside on my pix but there is still the situation, i mean i'm still getting the "black" screen on my MS-DOS window wich gives the impresion that the port that i'm telnet to is open when it is not.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you have any idea what else could be causing this??&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 29 Aug 2009 05:17:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-gives-the-impression-that-a-port-is-open-when-it-is-not/m-p/1201944#M859791</guid>
      <dc:creator>alfonso.cornejo</dc:creator>
      <dc:date>2009-08-29T05:17:29Z</dc:date>
    </item>
    <item>
      <title>Re: Pix gives the impression that a port is open when it is not</title>
      <link>https://community.cisco.com/t5/network-security/pix-gives-the-impression-that-a-port-is-open-when-it-is-not/m-p/1201945#M859792</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;read the url again:-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/docs/security/asa/asa72/command/reference/s1_72.html#wp1290652" target="_blank"&gt;http://www.cisco.com/en/US/docs/security/asa/asa72/command/reference/s1_72.html#wp1290652&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 29 Aug 2009 05:54:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-gives-the-impression-that-a-port-is-open-when-it-is-not/m-p/1201945#M859792</guid>
      <dc:creator>andrew.prince</dc:creator>
      <dc:date>2009-08-29T05:54:00Z</dc:date>
    </item>
    <item>
      <title>Re: Pix gives the impression that a port is open when it is not</title>
      <link>https://community.cisco.com/t5/network-security/pix-gives-the-impression-that-a-port-is-open-when-it-is-not/m-p/1201946#M859793</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Andrew,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I read the document again and it seems that the commands that i have to configure are:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;service resetoutside&lt;/P&gt;&lt;P&gt;service resetinbound interface dmz&lt;/P&gt;&lt;P&gt;service resetinbound interface outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But i'm still getting the same situation, do you think this may be a bug issue or anything else?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The traffic is comming from the outside interface to a DMZ.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance for your help.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 29 Aug 2009 21:04:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-gives-the-impression-that-a-port-is-open-when-it-is-not/m-p/1201946#M859793</guid>
      <dc:creator>alfonso.cornejo</dc:creator>
      <dc:date>2009-08-29T21:04:46Z</dc:date>
    </item>
    <item>
      <title>Re: Pix gives the impression that a port is open when it is not</title>
      <link>https://community.cisco.com/t5/network-security/pix-gives-the-impression-that-a-port-is-open-when-it-is-not/m-p/1201947#M859794</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What exactly is your problem, I must be missing someting.  I thought you did NOT want to send the rest in the tcp session - as when this happens it indicates there is a device there.  Not really what you want a hacker to know - ideally you want the device ti silenty discard.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 30 Aug 2009 09:26:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-gives-the-impression-that-a-port-is-open-when-it-is-not/m-p/1201947#M859794</guid>
      <dc:creator>andrew.prince</dc:creator>
      <dc:date>2009-08-30T09:26:35Z</dc:date>
    </item>
    <item>
      <title>Re: Pix gives the impression that a port is open when it is not</title>
      <link>https://community.cisco.com/t5/network-security/pix-gives-the-impression-that-a-port-is-open-when-it-is-not/m-p/1201948#M859795</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The situation is this: i have two servers published to the internet using my pix (with a static nat) and with an access-list i have allowed access to them only to the http and smtp port but when you make a telnet lets say to the port 1024 wich is not allowed on your MS-DOS window you get a "black screen" that gives you the impresion that the port is open but it is not, actually i see the denied packets on the monitoring of the pix.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I know that the pix is blocking that traffic, wich is correct, but that impresion of the port open is causing me problems with the information security department, because they say that the "see" that i have all the ports open but they are not.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That's why i put those commands, to send the tcp reset and get the normal message when you make a telnet to an ip address to a port that is blocked.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 30 Aug 2009 16:25:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-gives-the-impression-that-a-port-is-open-when-it-is-not/m-p/1201948#M859795</guid>
      <dc:creator>alfonso.cornejo</dc:creator>
      <dc:date>2009-08-30T16:25:10Z</dc:date>
    </item>
    <item>
      <title>Re: Pix gives the impression that a port is open when it is not</title>
      <link>https://community.cisco.com/t5/network-security/pix-gives-the-impression-that-a-port-is-open-when-it-is-not/m-p/1201949#M859796</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm sorry, but your security department are way off, getting a black screen in dos does not mean anything, use a port scanner, or some other tool like nmap to test with. Also, if you care about security you don't want to send tcp resets when you are blocking something, this will tell the scanner that the port is actively being blocked ie. that there is a firewall or router acl.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 30 Aug 2009 21:37:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-gives-the-impression-that-a-port-is-open-when-it-is-not/m-p/1201949#M859796</guid>
      <dc:creator>jan.nielsen</dc:creator>
      <dc:date>2009-08-30T21:37:36Z</dc:date>
    </item>
    <item>
      <title>Re: Pix gives the impression that a port is open when it is not</title>
      <link>https://community.cisco.com/t5/network-security/pix-gives-the-impression-that-a-port-is-open-when-it-is-not/m-p/1201950#M859798</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, i just did a test with nmap and the report of the scan says that "all" the ports are open (from 1 to 65535) but in the monitoring of my pix i see all the "denies" of the huge amount of ports that are blocked.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;what do you think could be causing this condition?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 31 Aug 2009 13:16:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-gives-the-impression-that-a-port-is-open-when-it-is-not/m-p/1201950#M859798</guid>
      <dc:creator>alfonso.cornejo</dc:creator>
      <dc:date>2009-08-31T13:16:39Z</dc:date>
    </item>
    <item>
      <title>Re: Pix gives the impression that a port is open when it is not</title>
      <link>https://community.cisco.com/t5/network-security/pix-gives-the-impression-that-a-port-is-open-when-it-is-not/m-p/1201951#M859799</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That is just not possible - if you have a machine on the "outside" of your firewall and ALL ports are comming back as open - then you are using nmap incorrectly.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 01 Sep 2009 10:14:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-gives-the-impression-that-a-port-is-open-when-it-is-not/m-p/1201951#M859799</guid>
      <dc:creator>andrew.prince</dc:creator>
      <dc:date>2009-09-01T10:14:27Z</dc:date>
    </item>
  </channel>
</rss>

