TO UNSUBSCRIBE: email "unsubscribe issforum" in the body of your message to
[EMAIL PROTECTED]  Contact [EMAIL PROTECTED] for help with any problems!
----------------------------------------------------------------------------

Hi everybody,
my name is Damiano Peres and I work for an Italian company (ISYI) which is
an ISS Partner in Italy.

We have a problem with RealSecure. There is a RS Network Engine outside the
Firewall, so it is on the Internet in stealth mode. The platform is NT, RS
is 3.2.1. We noticed that if we launch a second Port Scan immediatly after a
first one from two different machines (so from two different IP addresses),
RS doesn't detect the second Port Scan. If we launch the first Port Scan,
then wait more than 2 minutes, and then launch the second Port Scan, RS
detects both. The Scans I am talking about are of course aimed to machines
inside the Firewall.

Please note that we placed a sniffer near RS to prove that all the Port
Scans actually reach RS.

There is another thing that seems very strange to us. Consider a Port Scan
aimed to the whole Internet-visible Class C. RS detects all those Scans to
all the targets if we do it one first time. If we do it again after it's
finished from the same machine (so we are not in the previous case), RS
doesn't detect the second, the third, the fourth...all the following Scans
ONLY for a particular target, wich is a IIS Web Server. If you shutdown and
restart the Engine, it will begin to detect the Scan again for that Target.

Thank you very much in advance for any help!

Best regards

Damiano Peres
[EMAIL PROTECTED]



Reply via email to