Hi List- I’m doing a review of a few fairly simple web servers behind a firewall (I’m guessing it’s a checkpoint). Before using Nessus I ran Nmap - I did a TCP connect scan looking for only a few specific ports (80,443,23,22,21,8080) and the results were accurate (manually verified). However, when scanning using Nessus, the port scans do not pick up any active ports. I’ve tried using and setting all of the various options and none seem to help, a FIN scan reports all ports as open (which I expected since this is a windows shop) but syn and connect scans report nothing open, and I know these are live hosts - the only result on the scan reports has been that the host is up. I’m hoping someone can take a look at this and clue me in on my newbie error. I am running Nessus 2.0.9, Nmap 3.0, the WX client, and am scanning via 56K modem. I have pasted what I think are the relevant parts of my nessusWX file below: begin(SERVER_PREFS) max_hosts = 2 max_checks = 3 port_range = 21-23,53,69,80,111,119,137,139,443,445,593,1477,1478,3018,7937, 7938,8080,8081 checks_read_timeout = 5 non_simult_ports = 139, 445 plugins_timeout = 320 safe_checks = no auto_enable_dependencies = yes ←-snip-→ begin(PLUGINS_PREFS) Nmap[radio]:TCP scanning technique : = SYN scan Nmap[checkbox]:UDP port scan = no Nmap[checkbox]:RPC port scan = no Nmap[checkbox]:Ping the remote host = no Nmap[checkbox]:Identify the remote OS = yes Nmap[checkbox]:Use hidden option to identify the remote OS = no Nmap[checkbox]:Fragment IP packets (bypasses firewalls) = yes Nmap[checkbox]:Get Identd info = no Nmap[radio]:Port range = User specified range Nmap[checkbox]:Do not randomize the order in which ports are scanned = yes Nmap[entry]:Source port : = any Nmap[entry]:Data length : = Nmap[entry]:Ports scanned in parallel (max) = Nmap[radio]:Timing policy : = Normal Nmap[entry]:Host Timeout (ms) : = Nmap[entry]:Min RTT Timeout (ms) : = Nmap[entry]:Max RTT Timeout (ms) : = Nmap[entry]:Initial RTT timeout (ms) = Nmap[entry]:Minimum wait between probes (ms) = Ping the remote host[entry]:TCP ping destination port(s) : = 22;80;443 Ping the remote host[checkbox]:Do a TCP ping = yes Ping the remote host[checkbox]:Do an ICMP ping = no Ping the remote host[entry]:Number of retries (ICMP) : = 3 Ping the remote host[checkbox]:Make the dead hosts appear in the report = no Thanks in advance. ---------------------------------------------------------------------------- This message contains information which is privileged and confidential and is solely for the use of the intended recipient. If you are not the intended recipient, be aware that any review, disclosure, copying, distribution, or use of the contents of this message is strictly prohibited. If you have received this in error, please destroy it immediately and notify us at [EMAIL PROTECTED] _______________________________________________ Nessus mailing list [EMAIL PROTECTED] http://mail.nessus.org/mailman/listinfo/nessus
