
teChnology 81
If the connection handshake is completed with an ACK packet,
an entry in a connection table is maintained on the host and/or on
a firewall. e result is a further consumption of resources until the
connection times out or is reset. For that reason, it is important to
test the behavior of a scanner and determine whether or not a TCP
reset is sent to the host and how that behavior might affect your net-
work on a large scale. If it is possible that a large amount of scan-
ning will be performed through a firewall, then test this scenario.
e setup and breakdown of connections on a firewall are two of the
more processor-intensive tasks ...