Hi All,
how can I test Exploit Prevention Rule 3700 Port Scan, because when I tried to scan with Port scanner Advanced or Nmap one both applications I ran the port scan and it provides me all the details although the ENS reported that the NIPS block it but still I saw all the ports that are opened?
so someone can tell me how to test it and what this rule should block?
Solved! Go to Solution.
Hi @DimaV,
Good day to you!
The way you tested the rule was right, the rule ID 3700 blocks/reports the remote IP address that tried to perform a TCP port scan. It does not block the ports but it blacklists the remote IP address for the number of seconds that you have defined in the ENS exploit prevention policy.
Thanks,
AJ
Hi @DimaV,
Good day to you!
The way you tested the rule was right, the rule ID 3700 blocks/reports the remote IP address that tried to perform a TCP port scan. It does not block the ports but it blacklists the remote IP address for the number of seconds that you have defined in the ENS exploit prevention policy.
Thanks,
AJ
Corporate Headquarters
6220 America Center Drive
San Jose, CA 95002 USA