PC Review


Reply
Thread Tools Rating: Thread Rating: 2 votes, 1.00 average.

Disable the Stealth Mode in Windows Firewall

 
 
OgL
Guest
Posts: n/a
 
      27th Nov 2009
Hello,
is there any way to disable the Stealth mode "feature" in the Windows Vista
(Seven, Server 2008, Server 2008 R2)? Here
http://technet.microsoft.com/en-us/library/dd448557(WS.10).aspx the MS says:
"Stealth mode is enabled by default", but nothing about disabling. This
behavior is against RFC and dramatically slows down security scanners
installed in our network. So, is there any way of using windows firewall and
being nice RFC compliant boy?

Thanks,
Glatz

 
Reply With Quote
 
 
 
 
Andy Medina
Guest
Posts: n/a
 
      27th Nov 2009
Specifically which RFC? What kind of "security scanning" are you doing,
since it is *good* to have stealth mode active for security reasons.

"OgL" <(E-Mail Removed)> wrote in message
news:A70E6DB0-5647-40E4-8C66-(E-Mail Removed)...
> Hello,
> is there any way to disable the Stealth mode "feature" in the Windows
> Vista (Seven, Server 2008, Server 2008 R2)? Here
> http://technet.microsoft.com/en-us/library/dd448557(WS.10).aspx the MS
> says: "Stealth mode is enabled by default", but nothing about disabling.
> This behavior is against RFC and dramatically slows down security scanners
> installed in our network. So, is there any way of using windows firewall
> and being nice RFC compliant boy?
>
> Thanks,
> Glatz


 
Reply With Quote
 
OgL
Guest
Posts: n/a
 
      28th Nov 2009
> Specifically which RFC?
##############
RFC793 - Transmission Control Protocol
..
..
3.4. Establishing a connection
..
..
..
If the connection does not exist (CLOSED) then a reset is sent in response
to any incoming segment except another reset. In particular, SYNs addressed
to a non-existent connection are rejected by this means.
..
..
..
################
RFC792 INTERNET CONTROL MESSAGE PROTOCOL

If, in the destination host, the IP module cannot deliver the datagram
because the indicated protocol module or process port is not active, the
destination host may send a destination unreachable message to the source
host.
###############


> What kind of "security scanning" are you doing,

It doesn't matter (NESSUS).

> since it is *good* to have stealth mode active for security reasons.

I do not agree with that. But again, it does not matter. Simply, I want to
disable that "feature". The windows firewall is the only one I know, which
behave this way by default. When firewall is off, the windows machines act
as expected.

Glatz


 
Reply With Quote
 
Root Kit
Guest
Posts: n/a
 
      28th Nov 2009
On Fri, 27 Nov 2009 16:03:49 -0700, "Andy Medina"
<(E-Mail Removed)> wrote:

>Specifically which RFC? What kind of "security scanning" are you doing,
>since it is *good* to have stealth mode active for security reasons.


The so called "Stealth mode" adds nothing in terms of security.
 
Reply With Quote
 
Meinolf Weber [MVP-DS]
Guest
Posts: n/a
 
      28th Nov 2009
Hello OgL,

Not sure, but it sounds for me like the network discovery option which is
disabled by default:
http://windows.microsoft.com/en-US/w...work-discovery

Best regards

Meinolf Weber
Disclaimer: This posting is provided "AS IS" with no warranties, and confers
no rights.
** Please do NOT email, only reply to Newsgroups
** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm


> Hello,
> is there any way to disable the Stealth mode "feature" in the Windows
> Vista
> (Seven, Server 2008, Server 2008 R2)? Here
> http://technet.microsoft.com/en-us/library/dd448557(WS.10).aspx the MS
> says:
> "Stealth mode is enabled by default", but nothing about disabling.
> This
> behavior is against RFC and dramatically slows down security scanners
> installed in our network. So, is there any way of using windows
> firewall and
> being nice RFC compliant boy?
> Thanks,
> Glat



 
Reply With Quote
 
OgL
Guest
Posts: n/a
 
      28th Nov 2009
IMHO this option enables/disables using of LLTD protocol. Anyway, it is
turned on on my machine.

Thanks,
Glatz

"Meinolf Weber [MVP-DS]" <meiweb@(nospam)gmx.de> wrote in message
news:(E-Mail Removed)...
> Hello OgL,
>
> Not sure, but it sounds for me like the network discovery option which is
> disabled by default:
> http://windows.microsoft.com/en-US/w...work-discovery



 
Reply With Quote
 
 
 
Reply

Thread Tools
Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Disable the Stealth Mode in Windows Firewall OgL Windows Vista General Discussion 5 28th Nov 2009 02:13 PM
Closing ports to stealth mode Zen Andreas Windows Networking 3 10th Feb 2005 08:48 PM
RE: WinXP SP2 Firewall tested-all Stealth =?Utf-8?B?QWxleF9NYXN0cmFuZG9fSnIu?= Windows XP New Users 0 3rd Sep 2004 05:21 AM
Re: WinXP SP2 Firewall TESTED--ALL STEALTH gls858 Windows XP Basics 0 2nd Sep 2004 07:49 PM
The firewall cannot achieve perfect internet stealth with ICS enabled. The Black Wibble Windows XP Beta 1 26th Jun 2004 01:55 AM


Features
 

Advertising
 

Newsgroups
 


All times are GMT +1. The time now is 08:12 PM.