TMS zl Management and Configuration Guide ST.1.0.090213
6-18
Intrusion Detection and Prevention
Threat Detection and Prevention
Figure 6-7. TCP FIN Scan, Open Port
If the port is open, the host does not return a packet because the FIN packet
is not part of an established connection.
TCP ACK Scan
In this scan, the attacker attempts to discover which TCP ports on a host are
filtered by a firewall by sending an unsolicited acknowledge (ACK) packet to
a particular port.
Figure 6-8. TCP ACK Scan, Filtered Port
If the port is filtered, the host returns either nothing or an ICMP Destination
Unreachable packet.
Figure 6-9. TCP ACK Scan, Unfiltered Port