Old 11-29-2011, 06:57 AM   #1 (permalink)
Newbie
 
Join Date: Aug 2008
Posts: 9
zac1333 is on a distinguished road
Default Untangle Fails PCI Scan

Hello,

We are going through a PCI Compliance audit, and they did an external scan on our Untangle firewall running 9.0.2. They said it failed because of this - http://www.kb.cert.org/vuls/id/415294#systems.

I read through it and have a basic understanding of what they are saying, but how in the heck would I adjust/fix the Untangle to pass?
zac1333 is offline  
Old 11-29-2011, 07:00 AM   #2 (permalink)
Untangle Ninja
 
proactivens's Avatar
 
Join Date: Sep 2008
Location: Greensburg, Pa
Posts: 2,307
proactivens is on a distinguished road
Send a message via Skype™ to proactivens
Default

http://forums.untangle.com/installat...-untangle.html
Search will turn up many threads about this issue and how to take care of it. I'm not trying to be one of those RTFM idiots, but this one has been discussed at length for years. The above thread should give all you need to pass though
__________________
www.untangleappliances.com
Toll Free: 866-794-8879
UNTANGLE PLATINUM PARTNER
Follow us at spiceworks!
proactivens is offline  
Old 11-29-2011, 08:06 AM   #3 (permalink)
Untangle Ninja
 
sky-knight's Avatar
 
Join Date: Apr 2008
Location: Phoenix, AZ
URLs submitted: 8
Posts: 15,454
sky-knight is on a distinguished road
Default

That's a new one...

Now is about the time I point out that Untangle doesn't support BGP, doesn't use BGP, and therefore this vulnerability is moot.

The question is, why is it triggering?
__________________
Rob Sandling, BS:SWE, MCP
Intouch Technology
Phone: 480-272-9889
rob@intouchtechllc.com

UntangleAppliances.com
Phone: 866-794-8879
sky-knight is offline  
Old 11-29-2011, 08:15 AM   #4 (permalink)
Untangle Junkie
 
dmorris's Avatar
 
Join Date: Nov 2006
Location: San Mateo, CA
URLs submitted: 10
Posts: 10,611
dmorris is on a distinguished road
Default

Its probably basing the predictability of sequence numbers off a port forward to a machine with a different TCP stack.

I'd start by disabling all your port forwards and any bypass rules you've added.
__________________
Attention: Support and help on the Untangle Forums is provided by
volunteers and community members like yourself.
If you need Untangle support please call or email support@untangle.com
dmorris is offline  
Old 11-29-2011, 11:19 AM   #5 (permalink)
Untangle Ninja
 
sky-knight's Avatar
 
Join Date: Apr 2008
Location: Phoenix, AZ
URLs submitted: 8
Posts: 15,454
sky-knight is on a distinguished road
Default

I just did some Googling on this and I'm with DMorris. Is TCP 179 is forwarded to something?
__________________
Rob Sandling, BS:SWE, MCP
Intouch Technology
Phone: 480-272-9889
rob@intouchtechllc.com

UntangleAppliances.com
Phone: 866-794-8879
sky-knight is offline  
Closed Thread

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 06:24 AM.


© 2010 Untangle, Inc. All Rights Reserved.   SEO by vBSEO 3.6.0 PL2