<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: port 2000 and NMAP in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/port-2000-and-nmap/m-p/75183#M41896</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What is the traffic end reason in the traffic logs? Which application is recognized, again in the traffic logs? Which applications did you allow in the corresponding rule?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Benjamin&lt;/P&gt;</description>
    <pubDate>Thu, 24 Mar 2016 17:46:16 GMT</pubDate>
    <dc:creator>BenjAudy.MTL</dc:creator>
    <dc:date>2016-03-24T17:46:16Z</dc:date>
    <item>
      <title>port 2000 and NMAP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/port-2000-and-nmap/m-p/75175#M41893</link>
      <description>&lt;P&gt;I'm having an issue where any traffic through palo alto using destination port 2000 will create a tcp handshake and no more traffic will pass. I've talked to support and no traffic is being dropped by the firewall. i've added a rule to allow tcp 2000 as a service so it shouldn't be doing anything with the appid and no difference in behavior.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Another odd thing i see is that if i nmap any host (existing or not) through the firewall tcp ports 2000 and 5060 show open. I'm assuming this is related.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;nmap X.X.X.X&amp;nbsp;-PN&lt;/P&gt;
&lt;P&gt;Starting Nmap 5.21 ( &lt;A href="http://nmap.org" target="_blank"&gt;http://nmap.org&lt;/A&gt; ) at 2016-03-24 11:19 CDT&lt;BR /&gt;Nmap scan report for&amp;nbsp;X.X.X.X&lt;BR /&gt;Host is up (0.00044s latency).&lt;BR /&gt;Not shown: 997 filtered ports&lt;BR /&gt;PORT STATE SERVICE&lt;BR /&gt;113/tcp closed auth&lt;BR /&gt;2000/tcp open cisco-sccp&lt;BR /&gt;5060/tcp open sip&lt;/P&gt;
&lt;P&gt;Nmap done: 1 IP address (1 host up) scanned in 6.58 seconds&lt;/P&gt;</description>
      <pubDate>Thu, 24 Mar 2016 16:20:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/port-2000-and-nmap/m-p/75175#M41893</guid>
      <dc:creator>Mat_FA</dc:creator>
      <dc:date>2016-03-24T16:20:37Z</dc:date>
    </item>
    <item>
      <title>Re: port 2000 and NMAP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/port-2000-and-nmap/m-p/75183#M41896</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What is the traffic end reason in the traffic logs? Which application is recognized, again in the traffic logs? Which applications did you allow in the corresponding rule?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Benjamin&lt;/P&gt;</description>
      <pubDate>Thu, 24 Mar 2016 17:46:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/port-2000-and-nmap/m-p/75183#M41896</guid>
      <dc:creator>BenjAudy.MTL</dc:creator>
      <dc:date>2016-03-24T17:46:16Z</dc:date>
    </item>
    <item>
      <title>Re: port 2000 and NMAP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/port-2000-and-nmap/m-p/75189#M41897</link>
      <description>&lt;P&gt;traffic end is ussually tcp-fin. Application is alwysa incomplete. rule allows any application and application default for service. i've also tried to do it with any application and tcp 2000 defined as the service. I should probably mention this is a messaging service that's been programmed to use port 2000 so it's not sccp (the normal expected app for 2000)&lt;/P&gt;</description>
      <pubDate>Thu, 24 Mar 2016 18:12:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/port-2000-and-nmap/m-p/75189#M41897</guid>
      <dc:creator>Mat_FA</dc:creator>
      <dc:date>2016-03-24T18:12:33Z</dc:date>
    </item>
    <item>
      <title>Re: port 2000 and NMAP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/port-2000-and-nmap/m-p/75219#M41899</link>
      <description>&lt;P&gt;As far as I know, the firewall cannot set the FIN flag on the TCP packets, so it must come from the server or appliance you're connecting to. My guess is that there must be something blocking the connection at the application level on the server end. If there was something blocking at a lower level (e.g. Windows firewall), NMAP would not say the port is open.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Benjamin&lt;/P&gt;</description>
      <pubDate>Thu, 24 Mar 2016 21:25:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/port-2000-and-nmap/m-p/75219#M41899</guid>
      <dc:creator>BenjAudy.MTL</dc:creator>
      <dc:date>2016-03-24T21:25:21Z</dc:date>
    </item>
    <item>
      <title>Re: port 2000 and NMAP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/port-2000-and-nmap/m-p/75234#M41902</link>
      <description>&lt;P&gt;Application incomplete means that TCP 3-way handshake did not complete.&lt;/P&gt;
&lt;P&gt;I suggest to take packet capture on the firewall (under Monitor tab) and verify if you see all syn, syn ack and ack going by and who sends tcp fin.&lt;/P&gt;</description>
      <pubDate>Fri, 25 Mar 2016 05:23:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/port-2000-and-nmap/m-p/75234#M41902</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2016-03-25T05:23:49Z</dc:date>
    </item>
    <item>
      <title>Re: port 2000 and NMAP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/port-2000-and-nmap/m-p/75255#M41917</link>
      <description>&lt;P&gt;It's definitly not an issue on the server. same subnet traffic connects just fine. it's only through the firewall. tcp handshake shows 3 way. but let's take that example out of the question.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;i have 2 zones a trust and a DMZ the rule is to allow all from trust to dmz any application any service. If i scan that subnet it shows 2000 open on every single ip in that subnet if a host exists or not.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;if i telnet to that port on a host that doesn't even exist. i get a connection. nothing in arp table for this ip or anything.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;mabernathy@plnasops:~$ telnet x.x.x.x&amp;nbsp;2000&lt;BR /&gt;Trying x.x.x.x...&lt;BR /&gt;Connected to x.x.x.x.&lt;BR /&gt;Escape character is '^]'.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;^C^C^C^]&lt;/P&gt;
&lt;P&gt;telnet&amp;gt; quit&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;the traffic logs on this traffic shows aged-out.&lt;/P&gt;</description>
      <pubDate>Fri, 25 Mar 2016 15:08:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/port-2000-and-nmap/m-p/75255#M41917</guid>
      <dc:creator>Mat_FA</dc:creator>
      <dc:date>2016-03-25T15:08:14Z</dc:date>
    </item>
  </channel>
</rss>

