Firewalk (L4 determination)
An active reconnaissance network security tool that attempts to determine what layer 4
protocols a given IP forwarding device will pass (TCP/UDP)
Firewalk works by sending out TCP or UDP packets with a TTL one greater than the targeted
gateway
▪ If the gateway allows the traffic, it will forward the packets to the next hop where they will expire and
elicit an ICMP_TIME_EXCEEDED message. Else, it will likely drop the packets.