Q.
Why the TCP port 0 and 1 of Vigor Router are scanned in
CLOSE status after I turn on the Block TCP flag scan function
?
Vigor Router has a special firewall mechanism which can
confuse the OS Detection Tools when Vigor Router detects
the the scanning (tcp flag field) is abnormal. OS detection
is used to collect information like Operating System or
Application type and so on by TCP/UDP flag scan tools. After
enabling the "Block TCP flag scan" function, the
special mechanism will not respond the scan request according
to its real status. So the TCP port 0 and 1 are scanned
as CLOSE is not the real status of the TCP port status of
Vigor Router but the fake status to annoy the scanner. If
you don??t want to activate the mechanism or you want to
let Vigor router respond the real port status, you may disable
the "Block TCP flag scan" feature.
Please go to the page of "Firewall>>DoS defense
Setup" to disable the "Block TCP flag scan"
option.

|