Port Scanning, but Monitoring is Off for Target Device

Comments

8 comments

  • Avatar
    Firewalla

    Tap on + button, tap on "device port scan" and turn off on your PC

    May I know if ESET will only send a warning, or will it block firewalla?

    0
    Comment actions Permalink
  • Avatar
    DevOps

    When you say + button, where exactly is that? I am on Firewalla Blue and if I pull up the device in question it shows Monitoring as disabled. So, I do believe that there should be no port scanning for the device.

    From the Security team's ESET logs it appears it's showing it as a warning, but is being blocked as well as the action.

    0
    Comment actions Permalink
  • Avatar
    DevOps

    Oops! I see the + button now within the app and located the Device Port Scan option. I was looking on the browser ui from my desktop and could not locate that option. Thanks! Will see how it goes.

    0
    Comment actions Permalink
  • Avatar
    DevOps

    Also, is Firewalla looking into a way for turning on device port scanning, but being able to opt certain devices out of that?

    0
    Comment actions Permalink
  • Avatar
    Firewalla

    You should be able to select which device to turn on for the device port scanning feature. did you see the selection Apply To section?

    0
    Comment actions Permalink
  • Avatar
    DevOps

    Thanks! I guess I should have slowed down a bit and dug into all the options more. When I went there first it didn't show me the additional options right away, so I thought it was a system wide on/off type of thing. I do see it now. I think it might be cool to do an inverse type of selection, like Apply to All except for devices you define. For example, in my case I have around 60 devices and I only wanted to exclude 2 devices from having port scans done. I did not see an easy way to just exclude those two and have it run for all others on my network by default.

    0
    Comment actions Permalink
  • Avatar
    Firewalla

    Okay, will let the team know this requirement.

    May I know if ESET will block firewalla after detecting the scan? or it just warn you? We have several cases from the consumer side, where the antivirus software will block the router (which is firewalla) and kill internet when detect scanning 

    0
    Comment actions Permalink
  • Avatar
    DevOps

    From the logs I received it does appear to warn and then block the port scanned. There are even some references in the log to it blocking the router's IP, but I still have network connectivity.

    0
    Comment actions Permalink

Please sign in to leave a comment.