Sorry for asking about such a common thing, but right now I'm writing an access-list for the subnet we gave to nessus. Since we have to route the scans my question is thus: can I get away with limiting *return* traffic to ports greater than 1023?
I know many attacks (probes) need to hit low ports like ftp, but does the reply need to come in on a low port? I'm aware of the no-firewall policy for vulnerability scanners, but it's almost physically impossible for me to get my fingers to type "permit ip any any" on a cisco box. Boy, I'm nervous just typing it here. :) ===== ----------------------------------------------------------- Intelligence is being smarter than your boss. Wisdom is keeping it to yourself. ----------------------------------------------------------- __________________________________________________ Do You Yahoo!? Try FREE Yahoo! Mail - the world's greatest free email! http://mail.yahoo.com/
