<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: NMAP scan and CPAS in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NMAP-scan-and-CPAS/m-p/235999#M45771</link>
    <description>&lt;P&gt;Yup, that's true. Good point!&lt;/P&gt;</description>
    <pubDate>Tue, 17 Dec 2024 12:34:46 GMT</pubDate>
    <dc:creator>JasMan</dc:creator>
    <dc:date>2024-12-17T12:34:46Z</dc:date>
    <item>
      <title>NMAP scan and CPAS</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NMAP-scan-and-CPAS/m-p/235981#M45763</link>
      <description>&lt;P&gt;Hi folks,&lt;BR /&gt;&lt;BR /&gt;During a penetration test in our network a Nmap scan on port 80 for a complete /16 subnet was started. The source IP address was allowed to reach each IP address and excluded from the most inspections. But during the scan the load of the firewall reached 99% and the traffic flow nearly stopped.&lt;/P&gt;&lt;P&gt;Our service provider was not able to identify the reason. From my analyses later that day it happened due to CPAS (&lt;A href="https://support.checkpoint.com/results/sk/sk179804" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk179804&lt;/A&gt;).&lt;/P&gt;&lt;P&gt;CPAS act as a responder for HTTP requests and do a 3-way-handshake for each requested IP address, regardless if the address is online or not. It keeps sessions to offline IP addresses for 30 seconds open.&lt;/P&gt;&lt;P&gt;That means an aggressive Nmap scan would cause a lot of parallel new connections and a high load on the firewall until it stops working.&lt;/P&gt;&lt;P&gt;Is this an expected behaviour? Is it possible to reduce the 30 seconds for each connection or which is the suggested value? Any other suggestions to prevent such an issue?&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;&lt;P&gt;Jas Man&lt;/P&gt;</description>
      <pubDate>Tue, 17 Dec 2024 10:38:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NMAP-scan-and-CPAS/m-p/235981#M45763</guid>
      <dc:creator>JasMan</dc:creator>
      <dc:date>2024-12-17T10:38:50Z</dc:date>
    </item>
    <item>
      <title>Re: NMAP scan and CPAS</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NMAP-scan-and-CPAS/m-p/235983#M45764</link>
      <description>&lt;P&gt;This SK's will maybe help you out:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk110873" target="_blank" rel="noopener noreferrer"&gt;https://support.checkpoint.com/results/sk/sk110873&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;This one is mostly about DDOS but it also speaks regarding port scans&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk112241" target="_blank" rel="noopener noreferrer"&gt;https://support.checkpoint.com/results/sk/sk112241&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 17 Dec 2024 10:54:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NMAP-scan-and-CPAS/m-p/235983#M45764</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2024-12-17T10:54:35Z</dc:date>
    </item>
    <item>
      <title>Re: NMAP scan and CPAS</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NMAP-scan-and-CPAS/m-p/235984#M45765</link>
      <description>&lt;P&gt;Using NMAP to aggressively scan the own network (best done from inside!) is an old joke that never seems to die... So this is expected behaviour.&lt;/P&gt;</description>
      <pubDate>Tue, 17 Dec 2024 10:54:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NMAP-scan-and-CPAS/m-p/235984#M45765</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2024-12-17T10:54:43Z</dc:date>
    </item>
    <item>
      <title>Re: NMAP scan and CPAS</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NMAP-scan-and-CPAS/m-p/235992#M45767</link>
      <description>&lt;P&gt;The second SK is very interessting. I'll check. Thx.&lt;/P&gt;</description>
      <pubDate>Tue, 17 Dec 2024 11:56:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NMAP-scan-and-CPAS/m-p/235992#M45767</guid>
      <dc:creator>JasMan</dc:creator>
      <dc:date>2024-12-17T11:56:24Z</dc:date>
    </item>
    <item>
      <title>Re: NMAP scan and CPAS</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NMAP-scan-and-CPAS/m-p/235993#M45768</link>
      <description>&lt;P&gt;They wanted to identify unknown systems in our network which listen to http and other "bad services". I would say it's a justified action. &lt;span class="lia-unicode-emoji" title=":smiling_face_with_halo:"&gt;😇&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 17 Dec 2024 12:02:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NMAP-scan-and-CPAS/m-p/235993#M45768</guid>
      <dc:creator>JasMan</dc:creator>
      <dc:date>2024-12-17T12:02:08Z</dc:date>
    </item>
    <item>
      <title>Re: NMAP scan and CPAS</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NMAP-scan-and-CPAS/m-p/235994#M45769</link>
      <description>&lt;P&gt;So you should configure it not as an aggressive NMAP scan, but to proceed only very slowly and carefully !&lt;/P&gt;</description>
      <pubDate>Tue, 17 Dec 2024 12:14:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NMAP-scan-and-CPAS/m-p/235994#M45769</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2024-12-17T12:14:35Z</dc:date>
    </item>
    <item>
      <title>Re: NMAP scan and CPAS</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NMAP-scan-and-CPAS/m-p/235999#M45771</link>
      <description>&lt;P&gt;Yup, that's true. Good point!&lt;/P&gt;</description>
      <pubDate>Tue, 17 Dec 2024 12:34:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NMAP-scan-and-CPAS/m-p/235999#M45771</guid>
      <dc:creator>JasMan</dc:creator>
      <dc:date>2024-12-17T12:34:46Z</dc:date>
    </item>
  </channel>
</rss>

