
Firewall Wizards mailing list archives
Re: Netscreen firewall and portscans?
From: TDyson () sybex com
Date: Wed, 6 Feb 2002 07:45:36 -0800
Yeah. Netscreens are a paranoid. Any traffic from a single source that uses a sequence of return ports, like HTTP 1.0 with a page with lots of elements as you mentioned, will cause Netscreen to cry "Wolf!". I have a canned e-mail I send back to the admins. It's always cool when I can say, "Let me guess. You have a Netscreen Firewall." Makes me look psychic. In our case the traffic always comes from one of our virtual IP addresses, so I know it is all response traffic. Thom Dyson Director of Information Services Sybex, Inc. On 2/5/02 2:51:08 PM, Tracy R Reed <treed () ultraviolet org> wrote:
I think it's just lame IDS systems out there (possibly all Netscreen systems) giving false alarms. We have some webpages with lots of small graphics. My theory is that the IDS sees a flurry of packets going back
to
some system behind his firewall all at different port numbers in a short amount of time and flags it as a portscan regardless of whether SYN was set or not. Anyone else have experience or heard of such false alarms? It is really annoying getting reports of portscans all the time because
if
we do someday get owned and someone scans we might ignore the report. -- Tracy Reed http://www.ultraviolet.org "She moves in mysterious ways"
_______________________________________________ firewall-wizards mailing list firewall-wizards () nfr com http://list.nfr.com/mailman/listinfo/firewall-wizards
Current thread:
- Netscreen firewall and portscans? Tracy R Reed (Feb 05)
- Re: Netscreen firewall and portscans? R. DuFresne (Feb 06)
- Re: Netscreen firewall and portscans? Pierre-Yves Bonnetain (Feb 06)
- Re: Netscreen firewall and portscans? Raul Duke (Feb 06)
- Re: Netscreen firewall and portscans? damiank (Feb 06)
- Re: Netscreen firewall and portscans? David Lang (Feb 06)
- Re: Netscreen firewall and portscans? Richard Johnson (Feb 07)
- <Possible follow-ups>
- RE: Netscreen firewall and portscans? Michael Walter (Feb 06)
- RE: Netscreen firewall and portscans? Christopher Lee (Feb 06)
- Re: Netscreen firewall and portscans? TDyson (Feb 06)
- Re: Netscreen firewall and portscans? Boni Bruno (Feb 06)
- Re: Netscreen firewall and portscans? Edward (Feb 06)
- RE: Netscreen firewall and portscans? Jason Lewis (Feb 07)
- Re: Netscreen firewall and portscans? Edward (Feb 06)
- Re: Netscreen firewall and portscans? Philip J. Koenig (Feb 07)