nmap'ing myself

2004-10-07 Thread Norm Vilmer
If there a better forum for discussing IPFW, please direct me there. I have a firewall machine running FreeBSD 4.10 connected between my DSL modem and my office switch. It does nat and has a basic set of IPFW rules. It is somewhat locked down (kern_securelevel = 1, other recommendations typical

Re: nmap'ing myself

2004-10-07 Thread Chuck Swiger
Norm Vilmer wrote: [ ... ] My question is: from a well configured firewall, Should I be able to nmap the public interface using a console session on the firewall itself? Sure. nmap should return close to zero open ports. Will allowing this compromising security of the machine? nmap doesn't

Re: nmap'ing myself

2004-10-07 Thread Norm Vilmer
Chuck Swiger wrote: Norm Vilmer wrote: [ ... ] My question is: from a well configured firewall, Should I be able to nmap the public interface using a console session on the firewall itself? Sure. nmap should return close to zero open ports. Will allowing this compromising security of the

Re: nmap'ing myself

2004-10-07 Thread Chris Howells
On Thursday 07 October 2004 21:56, Norm Vilmer wrote: Sorry about the ambiguity, i was referring to loosening my firewall rules and other settings to allow nmap to work properly. If it should work, No. Why would you want to deliberately make it easy to make a port scan work? If you're a script

Re: nmap'ing myself

2004-10-07 Thread Alex de Kruijff
On Thu, Oct 07, 2004 at 11:22:34PM +0100, Chris Howells wrote: On Thursday 07 October 2004 21:56, Norm Vilmer wrote: Sorry about the ambiguity, i was referring to loosening my firewall rules and other settings to allow nmap to work properly. If it should work, No. Why would you want to