cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
454
Views
3
Helpful
2
Replies

Firewall vulnerability Testing

echelon360
Level 1
Level 1

Hi guys,

A firewall vulnerability test on the PIX is schedule for and i was wondering if anyone has some advice on this.Basically,some of the qtns i have

-I'm assuming a collection of software is needed to test the firewall (eg SAINT).Is there a list of other effective ones?

-What kinds of test should i be conducting (eg port scans,vulnerable services)

-Is there a site/resource that could provide aid in coming up with a Firewall test doc.

Appreciate any help provided ...thank you

1 Accepted Solution

Accepted Solutions

Patrick Iseli
Level 7
Level 7

Firewall Audit !

Use nessus istead of Saint. Saint is quiet old and not updated. http://www.nessus.org

Services to check are:

- IPSec

- ssh

- telnet

- snmp

- https

- http

- icmp

Perform a general portscan with "nmap" to map open ports (-sS -P0). Then start a vulnerability scanner.

Doc about that can be found on:

http://www.google.ca/search?hl=en&q=firewall+piercing&btnG=Google+Search&meta=

http://www.sans.org/rr

sincerely

Patrick

View solution in original post

2 Replies 2

Patrick Iseli
Level 7
Level 7

Firewall Audit !

Use nessus istead of Saint. Saint is quiet old and not updated. http://www.nessus.org

Services to check are:

- IPSec

- ssh

- telnet

- snmp

- https

- http

- icmp

Perform a general portscan with "nmap" to map open ports (-sS -P0). Then start a vulnerability scanner.

Doc about that can be found on:

http://www.google.ca/search?hl=en&q=firewall+piercing&btnG=Google+Search&meta=

http://www.sans.org/rr

sincerely

Patrick

mtawafig
Level 1
Level 1

nessus can help