Windows Vista Tips

Windows Vista Tips > Newsgroups > Windows Vista General Discussion > Disable the Stealth Mode in Windows Firewall

Reply
Thread Tools Display Modes

Disable the Stealth Mode in Windows Firewall

 
 
OgL
Guest
Posts: n/a

 
      11-27-2009
Hello,
is there any way to disable the Stealth mode "feature" in the Windows Vista
(Seven, Server 2008, Server 2008 R2)? Here
http://technet.microsoft.com/en-us/l...57(WS.10).aspx the MS says:
"Stealth mode is enabled by default", but nothing about disabling. This
behavior is against RFC and dramatically slows down security scanners
installed in our network. So, is there any way of using windows firewall and
being nice RFC compliant boy?

Thanks,
Glatz

 
Reply With Quote
 
 
 
 
Andy Medina
Guest
Posts: n/a

 
      11-27-2009
Specifically which RFC? What kind of "security scanning" are you doing,
since it is *good* to have stealth mode active for security reasons.

"OgL" <> wrote in message
news:A70E6DB0-5647-40E4-8C66-...
> Hello,
> is there any way to disable the Stealth mode "feature" in the Windows
> Vista (Seven, Server 2008, Server 2008 R2)? Here
> http://technet.microsoft.com/en-us/l...57(WS.10).aspx the MS
> says: "Stealth mode is enabled by default", but nothing about disabling.
> This behavior is against RFC and dramatically slows down security scanners
> installed in our network. So, is there any way of using windows firewall
> and being nice RFC compliant boy?
>
> Thanks,
> Glatz


 
Reply With Quote
 
OgL
Guest
Posts: n/a

 
      11-28-2009
> Specifically which RFC?
##############
RFC793 - Transmission Control Protocol
..
..
3.4. Establishing a connection
..
..
..
If the connection does not exist (CLOSED) then a reset is sent in response
to any incoming segment except another reset. In particular, SYNs addressed
to a non-existent connection are rejected by this means.
..
..
..
################
RFC792 INTERNET CONTROL MESSAGE PROTOCOL

If, in the destination host, the IP module cannot deliver the datagram
because the indicated protocol module or process port is not active, the
destination host may send a destination unreachable message to the source
host.
###############


> What kind of "security scanning" are you doing,

It doesn't matter (NESSUS).

> since it is *good* to have stealth mode active for security reasons.

I do not agree with that. But again, it does not matter. Simply, I want to
disable that "feature". The windows firewall is the only one I know, which
behave this way by default. When firewall is off, the windows machines act
as expected.

Glatz


 
Reply With Quote
 
Root Kit
Guest
Posts: n/a

 
      11-28-2009
On Fri, 27 Nov 2009 16:03:49 -0700, "Andy Medina"
<> wrote:

>Specifically which RFC? What kind of "security scanning" are you doing,
>since it is *good* to have stealth mode active for security reasons.


The so called "Stealth mode" adds nothing in terms of security.
 
Reply With Quote
 
Meinolf Weber [MVP-DS]
Guest
Posts: n/a

 
      11-28-2009
Hello OgL,

Not sure, but it sounds for me like the network discovery option which is
disabled by default:
http://windows.microsoft.com/en-US/w...work-discovery

Best regards

Meinolf Weber
Disclaimer: This posting is provided "AS IS" with no warranties, and confers
no rights.
** Please do NOT email, only reply to Newsgroups
** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm


> Hello,
> is there any way to disable the Stealth mode "feature" in the Windows
> Vista
> (Seven, Server 2008, Server 2008 R2)? Here
> http://technet.microsoft.com/en-us/l...57(WS.10).aspx the MS
> says:
> "Stealth mode is enabled by default", but nothing about disabling.
> This
> behavior is against RFC and dramatically slows down security scanners
> installed in our network. So, is there any way of using windows
> firewall and
> being nice RFC compliant boy?
> Thanks,
> Glat



 
Reply With Quote
 
OgL
Guest
Posts: n/a

 
      11-28-2009
IMHO this option enables/disables using of LLTD protocol. Anyway, it is
turned on on my machine.

Thanks,
Glatz

"Meinolf Weber [MVP-DS]" <meiweb@(nospam)gmx.de> wrote in message
news:. com...
> Hello OgL,
>
> Not sure, but it sounds for me like the network discovery option which is
> disabled by default:
> http://windows.microsoft.com/en-US/w...work-discovery



 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
I also have an error 646 in Windows update. Please help. Jose Windows Update 12 01-09-2010 02:00 PM
Why is it Windows *7*? Charles Lavin Windows Vista General Discussion 46 01-07-2010 09:37 PM
Can download updates, but will not installs Peter Windows Update 4 11-16-2009 02:30 PM
windows stopped booting... Karim Windows Vista Installation 1 06-19-2007 09:16 PM
Vista won't boot, kernal issues Lt. Washburn Windows Vista Installation 3 03-30-2007 02:09 AM



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59