cancel
Showing results for 
Search instead for 
Did you mean: 

Who Me Too'd this topic

Disable TCP 1323 Timestamp response through Palo Alto Firewall?

L0 Member

Hi,

I'm wondering whether is there a way to set the PAN Firewall to detect and drop TCP 1323 Timestamp queries to servers?

According to some web vulnerabilities scanning reports, it is reccomended to disable the TCP Timestamp as it discloses server uptime information, allowing attackers to guess the OS patch status.

In the recent Windows server OS (2008 and R2), disabling the TCP1323opts in registry doesn't seem to disable to the Timestamp responses as nmap scan test will still be able to get the uptime information.

In some web scanner reports, there are reccomendations to set in cisco firewalls to disable tcp timestamp eg, (no ip tcp timestamp).

Appreciate the reponse,

Regards,

Hans

Who Me Too'd this topic