r/Cisco
Access-list is not blocking SNMP UDP port 161 on VLAN after we run scan from WAN, (bug?)
- upvotes
- 8
- comments
- 13
Post
Highlighted: the lines this signal was extracted from
Recently the security team alerted that the UDP port looks open on switch C9300L (IOS 17.12.06) from WAN Basicaly we have a VLAN interface facing the WAN with an Access List for the SNMP service and a inbound access-list on the VLAN interface. we scanned the IP using nmap and the port looks opened then we added a new access list on the VLAN interface and the port was open (filtered), then the next day when i run the Nmap scan it looks like Open (not filtered) but we didnt make any change, it could be a bug? this is the result that tool Rapid7 display 2026-09-04T06:02:31 [INFO] [Thread: Scan 1603XX323:nmap:stdin] [Site: XX-XX] [X.X.X.X:161/UDP] OPEN (reason=udp-response:TTL=238) 2026-09-04T06:02:31 [INFO] [Thread: X.X.X.X:161/UDP] [Site: XX-XX] [Preference: 1.0] Attempting handshake via SNMP 2026-09-04T06:02:48 [DEBUG] [Thread: X.X.X.X:161/UDP] [Site: XX-XX] SNMP response received with no variable bindings 2026-09-04T06:02:48 [INFO] [Thread: X.X.X.X:161/UDP] [Site: XX-XX] Fingerprinted: SNMP 2026-09-04T06:02:48 [INFO] [Thread: convert-open-udp-ports-to-services@X.X.X.X] [Site: XX-XX] [X.X.X.X:161/udp] Running UDP service SNMP CONFIGURATION the extendend access list on the inteface was configured like this: Access-list BLOCK-FROM-WAN 10 deny udp 161 udp any any log 20 deny udp 162 udp any any log 30 permit any any the access below we applied was applied on...
Keep reading with a free account
The rest of this post, and every signal for Rapid7, is in your free account.
Also quoted as evidence
[comment u/Total1304] From my experience, with UDP services, rapid 7 likes to say that port is open even if there is no response (firewall drops packet) since it sometimes wants to see active ICMP packed rejected...