3 ms·
Won't the server need to accept a TCP connection to receive the cert? If so, the port will show as open. I suppose with UDP it is possible.
by lipnitsk 6y ago
Won't the server need to accept a TCP connection to receive the cert? If so, the port will show as open. I suppose with UDP it is possible.
- xorcist 6y agoIt does, but what you see is not a portscan, it is a lookup from the Shodan database and they store information about known services on the public Internet.
- achillean 6y agoShodan does something like a portscan of the entire Internet, albeit fewer ports than if you did nmap -p-
- achillean 6y agoI believe the recommended configuration is to run OpenVPN via UDP and only accept connections from trusted certificates. If you're running it on TCP then a scanner would be able to see that you have an open port but still can't see what's running on it.