Skip to main content
Rapid7Customer feedback

A commenter questions the reliability of Rapid7's UDP scanning, suggesting it may incorrectly report a port as open if the firewall drops the packet instead of sending an ICMP rejection.

What happened

Post: "Access-list is not blocking SNMP UDP port 161 on VLAN after we run scan from WAN, (bug?)"

Source

Post

Highlighted: the lines this signal was extracted from

Recently the security team alerted that the UDP port looks open on switch C9300L (IOS 17.12.06) from WAN Basicaly we have a VLAN interface facing the WAN with an Access List for the SNMP service and a inbound access-list on the VLAN interface. we scanned the IP using nmap and the port looks opened then we added a new access list on the VLAN interface and the port was open (filtered), then the next day when i run the Nmap scan it looks like Open (not filtered) but we didnt make any change, it could be a bug? this is the result that tool Rapid7 display 2026-09-04T06:02:31 [INFO] [Thread: Scan 1603XX323:nmap:stdin] [Site: XX-XX] [X.X.X.X:161/UDP] OPEN (reason=udp-response:TTL=238) 2026-09-04T06:02:31 [INFO] [Thread: X.X.X.X:161/UDP] [Site: XX-XX] [Preference: 1.0] Attempting handshake via SNMP 2026-09-04T06:02:48 [DEBUG] [Thread: X.X.X.X:161/UDP] [Site: XX-XX] SNMP response received with no variable bindings 2026-09-04T06:02:48 [INFO] [Thread: X.X.X.X:161/UDP] [Site: XX-XX] Fingerprinted: SNMP 2026-09-04T06:02:48 [INFO] [Thread: convert-open-udp-ports-to-services@X.X.X.X] [Site: XX-XX] [X.X.X.X:161/udp] Running UDP service SNMP CONFIGURATION the extendend access list on the inteface was configured like this: Access-list BLOCK-FROM-WAN 10 deny udp 161 udp any any log 20 deny udp 162 udp any any log 30 permit any any the access below we applied was applied on...

Keep reading with a free account

The rest of this post, and every signal for Rapid7, is in your free account.

Also quoted as evidence

  • [comment u/Total1304] From my experience, with UDP services, rapid 7 likes to say that port is open even if there is no response (firewall drops packet) since it sometimes wants to see active ICMP packed rejected...

Comments on the post

5 of 13 comments
  • “Is your ACL not wrong? Are you not blocking source port udp 161 instead of destination port udp 161? I think your ACL should look like: Access-list BLOCK-FROM-WAN 10 deny udp any any eq 161 log 20 deny udp any any eq 162 log 30 permit any any But I have to double check, long time since I worked with these.”

    u/Ok-Stretch249515 points · Sep 7, 2026View

  • “Try changing your ACL to match this: https://community.cisco.com/t5/network-security/open-udp-ports-123-161-500/td-p/4848977 Otherwise this is a know issue that Cisco has had some notorious design defects and bugs for years where port 161 responds to recon scanning (but doesn’t actually respond to snmp probes): Examples: https://community.cisco.com/t5/switching/nexus-snmp-acl-leaves-port-161-o”

    u/playdohsniffer4 points · Sep 7, 2026View

  • “I don't think you can use named ACLs on the snmp-server. I would also highly recommend migrating to SNMPv3.”

    u/wyohman3 points · Sep 7, 2026View

  • “Last time I put switches WAN side, I just configured no VLAN interface in the WAN VLAN and setup a management VLAN for management traffic. No IP, no attack surface.”

    u/egpigp3 points · Sep 7, 2026View

  • “You swapped source and destination on your ACLs”

    u/ComprehensiveBerry482 points · Sep 7, 2026View

Extracted by Autobound

From the Signal API record
Signal
Customer feedback

What this signalsUser posts often show product pain before it reaches reviews or churn.

Subreddit
r/Cisco

The full record

From the Signal API record

Numbers

Mentions
1

Details

Timing
Ongoing state
Category
Reliability
Virality
Medium
Post kind
Text
Prominence
Aside
Company's role
Vendor

Topics and mentions

Topics

  • vulnerability scanning
  • security
  • product reliability

Extraction

Sentiment
Negative
Detected
Sep 7, 2026
signal_type
reddit-company
signal_subtype
customerFeedback

Use this data

Get every Reddit signal for Rapid7 and the companies you sell to, in the tools you already use.

  1. Ask Claude about it

    Connect Autobound to Claude, Claude Code or Cursor with MCP. Then ask: “What changed at Rapid7 this week?”

  2. Send it to your own tools

    The Signal API returns Reddit signals for any list of companies as JSON, for your CRM, warehouse or app.

  3. Try it free

    Sign up and spend your free credits on the companies you sell to.

    Start Free1,000 free credits

The API returns more than this page shows

This page shows a preview. The full reddit-company record in the Signal API and MCP can also have these 8 fields. Some fields are empty for some signals.

Company

  • linkedin_urlValue in the API
  • industriesValue in the API
  • employee_count_lowValue in the API
  • employee_count_highValue in the API
  • revenueValue in the API
  • descriptionValue in the API

Signal

  • signal_nameValue in the API
  • associationValue in the API
Show the full JSONThe record on this page and the API request

GET /v1/signals/e8359b61-d6a8-53a8-a225-0458bf36c7a8 returns this record as JSON. POST /v1/companies/enrich returns every signal for rapid7.com.

{
  "signal_id": "e8359b61-d6a8-53a8-a225-0458bf36c7a8",
  "signal_type": "reddit-company",
  "signal_subtype": "customerFeedback",
  "detected_at": "2026-09-07T15:30:15+00:00",
  "company": {
    "name": "Rapid7",
    "domain": "rapid7.com"
  },
  "data": {
    "nsfw": false,
    "stage": "none",
    "awards": 0,
    "timing": "ongoing_state",
    "topics": [
      "vulnerability scanning",
      "security",
      "product reliability"
    ],
    "post_id": "1w9vbn4",
    "summary": "A commenter questions the reliability of Rapid7's UDP scanning, suggesting it may incorrectly report a port as open if the firewall drops the packet instead of sending an ICMP rejection.",
    "category": "reliability",
    "comments": [
      {
        "url": "https://www.reddit.com/r/Cisco/comments/1w9vbn4/comment/p8diexx/",
        "depth": 0,
        "score": 15,
        "author": "Ok-Stretch2495",
        "excerpt": "Is your ACL not wrong? Are you not blocking source port udp 161 instead of destination port udp 161?\n\n I think your ACL should look like:\n\n Access-list BLOCK-FROM-WAN\n\n 10 deny udp any any eq 161 log\n\n 20 deny udp any any eq 162 log\n\n 30 permit any any\n\n But I have to double check, long time since I worked with these.",
        "posted_at": "2026-09-07T16:04:47.000Z",
        "author_url": "https://www.reddit.com/user/Ok-Stretch2495/"
      },
      {
        "url": "https://www.reddit.com/r/Cisco/comments/1w9vbn4/comment/p8dg4if/",
        "depth": 0,
        "score": 4,
        "author": "playdohsniffer",
        "excerpt": "Try changing your ACL to match this:\nhttps://community.cisco.com/t5/network-security/open-udp-ports-123-161-500/td-p/4848977\n\n Otherwise this is a know issue that Cisco has had some notorious design defects and bugs for years where port 161 responds to recon scanning (but doesn’t actually respond to snmp probes):\n\n Examples:\nhttps://community.cisco.com/t5/switching/nexus-snmp-acl-leaves-port-161-o",
        "posted_at": "2026-09-07T15:54:40.000Z",
        "author_url": "https://www.reddit.com/user/playdohsniffer/"
      },
      {
        "url": "https://www.reddit.com/r/Cisco/comments/1w9vbn4/comment/p8ddmoo/",
        "depth": 0,
        "score": 3,
        "author": "wyohman",
        "excerpt": "I don't think you can use named ACLs on the snmp-server.\n\n I would also highly recommend migrating to SNMPv3.",
        "posted_at": "2026-09-07T15:43:33.000Z",
        "author_url": "https://www.reddit.com/user/wyohman/"
      },
      {
        "url": "https://www.reddit.com/r/Cisco/comments/1w9vbn4/comment/p8fus8t/",
        "depth": 0,
        "score": 3,
        "author": "egpigp",
        "excerpt": "Last time I put switches WAN side, I just configured no VLAN interface in the WAN VLAN and setup a management VLAN for management traffic. No IP, no attack surface.",
        "posted_at": "2026-09-07T22:35:15.000Z",
        "author_url": "https://www.reddit.com/user/egpigp/"
      },
      {
        "url": "https://www.reddit.com/r/Cisco/comments/1w9vbn4/comment/p8dslty/",
        "depth": 0,
        "score": 2,
        "author": "ComprehensiveBerry48",
        "excerpt": "You swapped source and destination on your ACLs",
        "posted_at": "2026-09-07T16:49:49.000Z",
        "author_url": "https://www.reddit.com/user/ComprehensiveBerry48/"
      },
      {
        "url": "https://www.reddit.com/r/Cisco/comments/1w9vbn4/comment/p8e0pnb/",
        "depth": 0,
        "score": 2,
        "author": "tablon2",
        "excerpt": "Assign your acl to snmp feature and use control plane host command to limit anything punting to CPU limited by mgmt VRF.",
        "posted_at": "2026-09-07T17:25:24.000Z",
        "author_url": "https://www.reddit.com/user/tablon2/"
      },
      {
        "url": "https://www.reddit.com/r/Cisco/comments/1w9vbn4/comment/p8ex71g/",
        "depth": 0,
        "score": 2,
        "author": "ThatOneIKnow",
        "excerpt": "Ignoring everything else, IOS-XE 17.12.06 should be updated, I think to 17.12.08. Especially when internet facing.",
        "posted_at": "2026-09-07T19:49:46.000Z",
        "author_url": "https://www.reddit.com/user/ThatOneIKnow/"
      },
      {
        "url": "https://www.reddit.com/r/Cisco/comments/1w9vbn4/comment/p8icz1c/",
        "depth": 0,
        "score": 1,
        "author": "Total1304",
        "excerpt": "Did you test via snmpwalk if it really responds?\n\n From my experience, with UDP services, rapid 7 likes to say that port is open even if there is no response (firewall drops packet) since it sometimes wants to see active ICMP packed rejected...",
        "posted_at": "2026-09-08T08:39:09.000Z",
        "author_url": "https://www.reddit.com/user/Total1304/"
      }
    ],
    "evidence": [
      "[post] this is the result that tool Rapid7 display",
      "[comment u/Total1304] From my experience, with UDP services, rapid 7 likes to say that port is open even if there is no response (firewall drops packet) since it sometimes wants to see active ICMP packed rejected..."
    ],
    "virality": "medium",
    "post_date": "2026-09-07T15:30:15.000Z",
    "post_kind": "text",
    "post_text": "Recently the security team alerted that the UDP port looks open on switch C9300L (IOS 17.12.06) from WAN\n\nBasicaly we have a VLAN interface facing the WAN with an Access List for the SNMP service and a inbound access-list on the VLAN interface.\n\nwe scanned the IP using nmap and the port looks opened then we added a new access list on the VLAN interface and the port was open (filtered), then the next day when i run the Nmap scan it looks like Open (not filtered) but we didnt make any change, it could be a bug?\n\nthis is the result that tool Rapid7 display\n\n2026-09-04T06:02:31 [INFO] [Thread: Scan 1603XX323:nmap:stdin]\n\n[Site: XX-XX] [X.X.X.X:161/UDP] OPEN (reason=udp-response:TTL=238)\n\n2026-09-04T06:02:31 [INFO] [Thread: X.X.X.X:161/UDP]\n\n[Site: XX-XX] [Preference: 1.0] Attempting handshake via SNMP\n\n2026-09-04T06:02:48 [DEBUG] [Thread: X.X.X.X:161/UDP]\n\n[Site: XX-XX] SNMP response received with no variable bindings\n\n2026-09-04T06:02:48 [INFO] [Thread: X.X.X.X:161/UDP]\n\n[Site: XX-XX] Fingerprinted: SNMP\n\n2026-09-04T06:02:48 [INFO] [Thread: convert-open-udp-ports-to-services@X.X.X.X]\n\n[Site: XX-XX] [X.X.X.X:161/udp] Running UDP service SNMP\n\nCONFIGURATION\n\nthe extendend access list on the inteface was configured like this:\n\nAccess-list BLOCK-FROM-WAN\n\n10 deny udp 161 udp any any log\n\n20 deny udp 162 udp any any log\n\n30 permit any any\n\nthe access below we applied was applied on...",
    "sentiment": "negative",
    "subreddit": "Cisco",
    "post_title": "Access-list is not blocking SNMP UDP port 161 on VLAN after we run scan from WAN, (bug?)",
    "prominence": "aside",
    "source_url": "https://www.reddit.com/r/Cisco/comments/1w9vbn4/accesslist_is_not_blocking_snmp_udp_port_161_on/",
    "entity_role": "vendor",
    "post_author": "oscarilllo",
    "upvote_ratio": 1,
    "mention_count": 1,
    "mention_surge": false,
    "subreddit_url": "https://www.reddit.com/r/Cisco/",
    "total_upvotes": 8,
    "comments_total": 13,
    "total_comments": 13,
    "post_author_url": "https://www.reddit.com/user/oscarilllo/",
    "signal_category": "feedback",
    "comments_included": 9
  }
}

Long text fields are shortened on this page.

Looking up one signal by its id is free. Enrich costs 2 credits per signal returned; a call with no results is free.