Sorry for asking about such a common thing, but right
now I'm writing an access-list for the subnet we gave
to nessus.  Since we have to route the scans my
question is thus: can I get away with limiting
*return* traffic to ports greater than 1023?

I know many attacks (probes) need to hit low ports
like ftp, but does the reply need to come in on a low
port?  I'm aware of the no-firewall policy for
vulnerability scanners, but it's almost physically
impossible for me to get my fingers to type "permit ip
any any" on a cisco box.  Boy, I'm nervous just typing
it here. :)

=====
-----------------------------------------------------------
Intelligence is being smarter than your boss.
Wisdom is keeping it to yourself.
-----------------------------------------------------------

__________________________________________________
Do You Yahoo!?
Try FREE Yahoo! Mail - the world's greatest free email!
http://mail.yahoo.com/

Reply via email to