For domain names that connect to WAF using a canonical name (CNAME) record, some scanners may incorrectly flag vulnerable ports as open because of responses from non-standard ports. However, these unconfigured ports do not pose a security risk because WAF 2.0 forwards service traffic only for ports that are configured in the console. WAF handles these ports as follows:
Configured ports: After a successful TCP three-way handshake, WAF forwards traffic on ports that are configured in the console.
Specific unconfigured ports: For the following unconfigured, non-standard ports, WAF returns a 410 (Gone) status code.
81, 82, 83, 84, 86, 87, 88, 89, 97, 800, 808, 1000, 1090, 3333, 3501, 3601, 5000, 5222, 6001, 6666, 7000, 7001, 7002, 7003, 7004, 7005, 7006, 7009, 7010, 7011, 7012, 7013, 7014, 7015, 7016, 7018, 7019, 7020, 7021, 7022, 7023, 7024, 7025, 7026, 7070, 7071, 7081, 7082, 7083, 7088, 7097, 7510, 7777, 7800, 8000, 8001, 8002, 8003, 8008, 8009, 8020, 8021, 8022, 8025, 8026, 8077, 8078, 8081, 8082, 8083, 8084, 8085, 8086, 8087, 8088, 8089, 8090, 8091, 8106, 8181, 8334, 8336, 8686, 8800, 8888, 8889, 8999, 9000, 9001, 9002, 9003, 9021, 9023, 9027, 9037, 9080, 9081, 9082, 9180, 9200, 9201, 9205, 9207, 9208, 9209, 9210, 9211, 9212, 9213, 9898, 9908, 9916, 9918, 9919, 9928, 9929, 9939, 9999, 10000, 10001, 10080, 12601, 28080, 33702, 48800, 4443, 5443, 6443, 7443, 8553, 8663, 9443, 9553, 9663, 18980
Other unconfigured ports: After a successful TCP three-way handshake, WAF immediately sends an RST packet to terminate the connection and does not forward any data.
Therefore, the vulnerable ports reported by scanners do not pose a security risk because WAF does not forward the associated traffic to the source server.
For a list of configurable ports for WAF 2.0, see Port support by edition.