Nessus
[Top] [All Lists]

Problems scanning across firewalls, Nessus 3.0.4

To: nessus@list.nessus.org
Subject: Problems scanning across firewalls, Nessus 3.0.4
From: Knut Hellebø <Knut.Hellebo@nho.hydro.com>
Date: Fri, 26 Jan 2007 12:09:12 +0100
Delivered-to: sp-com-lists@consult.net
Delivered-to: nessus-list1@securepoint.com
Delivered-to: nessus@list.nessus.org
List-archive: <http://mail.nessus.org/pipermail/nessus>
List-help: <mailto:nessus-request@list.nessus.org?subject=help>
List-id: Discussion of Nessus software <nessus.list.nessus.org>
List-post: <mailto:nessus@list.nessus.org>
List-subscribe: <http://mail.nessus.org/mailman/listinfo/nessus>, <mailto:nessus-request@list.nessus.org?subject=subscribe>
List-unsubscribe: <http://mail.nessus.org/mailman/listinfo/nessus>, <mailto:nessus-request@list.nessus.org?subject=unsubscribe>
Sender: nessus-bounces@list.nessus.org
User-agent: Thunderbird 1.5.0.9 (X11/20061206)
Regards,
I have two questions regarding Nessus scanning across firewalls. We have experienced network congestion/slowness when running Nessus inside a firewall protected network against hosts on the "other side". We use Nessus 3.0.4 and did not enable the nmap wrapper, ie using Nessus internal port scanner to scan all ports (65535). We limited checks to 5 simultaneous hosts, 5 simultaneous checks. We also turned on throttle scan and network congestion detection. Even though these precautions were taken, the network suffered. Apparently this was caused by ports being held open for too long during the scanning period, making the firewall drop old connections. Unfortunately I cannot reveal further details. Is Nessus 3 this intrusive ? What can be done to further limit network impact when testing across firewalls ?

***********************************************************************
NOTICE: This e-mail transmission, and any documents, files or previous
e-mail messages attached to it, may contain confidential or privileged
information. If you are not the intended recipient, or a person
responsible for delivering it to the intended recipient, you are
hereby notified that any disclosure, copying, distribution or use of
any of the information contained in or attached to this message is
STRICTLY PROHIBITED. If you have received this transmission in error,
please immediately notify the sender and delete the e-mail and attached
documents. Thank you.
***********************************************************************

_______________________________________________
Nessus mailing list
Nessus@list.nessus.org
http://mail.nessus.org/mailman/listinfo/nessus
<Prev in Thread] Current Thread [Next in Thread>