VPN enumeration first determines what the gateway is: the UDP IKE handshake on 500/4500 indicates IPsec, TCP 1723 indicates PPTP, a TLS web portal on 443 indicates an SSL-VPN appliance (and which vendor), and 1194 suggests OpenVPN. Then it extracts version and configuration: the IKE transform sets and whether aggressive mode is offered, the SSL-VPN portal's product and build (from the login page, headers, and resources), and TLS details. This drives everything, the protocol determines the attack, and for appliances the exact build maps to its pre-authentication exploit.
nmap -sU -p500,4500 --script ike-version <target> # IPsec/IKE
ike-scan -M <target>; ike-scan -A -M <target> # main vs aggressive mode transforms
nmap -p1723 --script pptp-version <target> # PPTP
curl -skI https://<target>/ # SSL-VPN portal product/headers
Subtopics#
- Protocol detection: identifying the VPN protocol and ports.
- Banner grabbing: version and product disclosure.