Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations derfloh on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

How to check open ports to secure ASAP ?

Status
Not open for further replies.

protos

IS-IT--Management
Apr 28, 2002
127
US
What is the easiest way/command to check open ports and monitor them on a daily basis to see who might be coming in or 'looking around' ??

thanks
 
I'll assume you know which ports are open by your config and ACLS etc. You really need to monitor that activity. Probably the most standard way is to enable syslog and monitor the logs.

Get a CCO login at
Here is pretty much everything you need to know about setting up and using PIX syslog:
for v6.2

Then you need a syslog monitor/analyzer of some kind. I use insideout - not the best but it works - Kiwi syslog is okay too I forget the link but you can search on "kiwi syslog" and come up with it easily.

You should run an outside port scan, on your entire public network, every so often as well. Shadow Security Scanner is good, nmap is very popular, retina is used by law enforcement - there are dozens and others here will have great suggestions I am sure.
 
Any Access-list statement that says "allow ..." is opening a port to an address. Of ycourse you need to be able to translate that address to a server or other device on your network.

If there is "any" at the end, everything is open.

If you see an "EQ 80" or some other "EQ" statement - that is your port that is opened.

You may see "GR some number' which is Greater Than

You may see "LT" which is Less than some port number
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top