Submit a ticketCall us

Announcing NCM 7.7
With NCM 7.7, you can examine the rules that make up an access control list for a Cisco ASA device. Then you can apply filters to display only rules that meet the specified criteria, order the rules by line number or by the hit count, and much more.
See new features and improvements.

Home > Success Center > Log & Event Manager (LEM) > TCP Port Scan

TCP Port Scan

Table of contents
Created by Bryan Davis, last modified by Aileen de Lara_ret on Jul 20, 2016

Views: 128 Votes: 0 Revisions: 3

Overview

This article provides brief information on Ndepth searches, and when they turn up TCP port scan coming from the firewall. 

Environment

  • LEM version 6.2
  • Sonicwall firewall
  • TCP Port Scan

Detail

When getting multiple port scans from a specific range of IP address, these IPs are non agent IPs not reporting to the LEM.

Find the rule fired, if no rule has been fired then the portscan alert is coming from the firewall.

 

 

 

Last modified
22:29, 19 Jul 2016

Tags

Classifications

Public