cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1440
Views
0
Helpful
2
Replies

Preventing web server scans on IPS

k.abillama
Level 1
Level 1

Hi,

IS there anyone who knows how to prevent a web server scan from getting the version of the IIS web server through a cisco IPS. I tried to set all the signatures that fired to ( drop packet, reset TCP connecction and drop connection inline ) but none worked. The results of a the vulnerability scan through the IPS are still showing the DNS version, IIS version. Can something be done on the IPS level?

Regards

2 Replies 2

Justin Westover
Level 1
Level 1

I don't know the answer but I am interested in a solution to this also.

Hello k.abillama,

Can you provide a packet capture of the scan? Please gather full-length packets so that the payload is included.

Thank you,

Blayne Dreier

Cisco TAC Escalation Team

**Please check out our Podcasts**

TAC Security Show: http://www.cisco.com/go/tacsecuritypodcast

TAC IPS Media Series: https://supportforums.cisco.com/docs/DOC-12758

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card