cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
805
Views
0
Helpful
9
Replies

How to test port in PIX 515E

Hi all ,

I config the acl in my PIX now , how can i know no another port is open ? have any software can ping 1-65536 port status?

pls advise , thx

Stanley

9 Replies 9

jmia
Level 7
Level 7

Stanley,

Goto www.grc.com and try 'ShieldsUP', this will probe your pix to check for any open ports and will give you a report. You can also make your pix invisible to the outside world or any port scanners by applying: icmp deny any outside - do this after you have tested with 'ShieldsUP'.

Hope this helps and let me know how you get on, pls rate this post if it helps you as others maybe looking for a similar answer.

Jay

Hi Jay ,

I visit your suggest site , but i found that only can scan the port up to 64 , have any advise ? thx

Stanley

Why not use NMAP, it's open source and free and runs and many platforms including Windows

http://www.insecure.org/nmap/

HTH

PD

Hi PD ,

I download it the nmap , but what command can scan the IP with the port range?

Stanley

Stanley,

If you click onto the 'All Service Port' buton this will scan up 1056 ports.

Jay

PS. You can also use NMAP as the other post suggested.

Hi Jay ,

Thanks for your advise , but i want scan all ports .

Stanley

try

nmap -p T:1-,U:1- -v

PD

Hi PD ,

i got the error message :

C:\1>nmap -P0 -p T:1-,U:1- -v www.yahoo.com

Starting nmap 3.75 ( http://www.insecure.org/nmap ) at 2004-12-22 00:32 中國標準

時間

Initiating SYN Stealth Scan against p16.www.scd.yahoo.com (66.94.230.47) [65535

ports] at 00:32

SYN Stealth Scan Timing: About 0.31% done; ETC: 04:14 (3:41:11 remaining)

after only wait long no feed back , what error?

Stanley

You did not enter a port to scan. Entering T:4,U:4 will scan much faster but you may lose some data depending on the network.

To scan the entire range you may want to scan with T5,U5. This may set off any IDS's you have.

nmap -sS -P0 -p 1-65535 -T5 host.

Use -v or -vv only if you need additional info.

C:\nmap-3.50>nmap -P0 -T4,U4 -p 80 www.yahoo.com

Starting nmap 3.50 ( http://www.insecure.org/nmap ) at 2004-12-21 11:56 Central Standard Time

Interesting ports on p21.www.re2.yahoo.com (68.142.226.52):

PORT STATE SERVICE

80/tcp filtered http

Nmap run completed -- 1 IP address (1 host up) scanned in 3.095 seconds

Review Cisco Networking for a $25 gift card