On Wed, Mar 13, 2002 at 02:10:35PM -0800, twig les wrote: > Sorry for asking about such a common thing, but right > now I'm writing an access-list for the subnet we gave > to nessus. Since we have to route the scans my > question is thus: can I get away with limiting > *return* traffic to ports greater than 1023?
No, some plugins open priviledged sockets (ie: source ports < 1023)
See the FAQ (www.nessus.org/doc/faq.html) for a sample firewall setup.
-- Renaud
