ACK flag scanning is useful to verify whether the server is blocked with firewalls, IPS, or other network security controls. As in the FIN scan, we will send an TCP ACK packet. No response or an ICMP error indicates the presence of a stateful firewall, as the port is filtered, and if we get back an RST-ACK, then the stateful firewall is absent:
![](https://static.packt-cdn.com/products/9781784399771/graphics/assets/84e5ca9b-6da0-42c8-8dca-2441361d4556.png)