---
title: "FAQ: Why is my port scanner reporting false positives?"
canonical: "https://docs.aryaka.com/space/KNOW/1275461644/FAQ%3A%20Why%20is%20my%20port%20scanner%20reporting%20false%20positives%3F"
format: markdown
---
This topic includes questions users often ask about applications such as port scanners reporting false positives.

### My port scanner reports that there are more clients on the network than expected. Why is this happening?

Aryaka Basic Firewall implements *dynamic application discovery* as described in the dynamic application discovery section of the [Basic Firewall](https://aryakadocs.atlassian.net/wiki/spaces/KNOW/pages/1275232263) topic.

As a part of detecting the application, the Aryaka Application Classification engine intercepts the TCP connection. When this happens, an application like a port scanner detects a response from Aryaka even if the destination being probed is not running on the network. This results in false positives.

### How can I overcome these false positives?

Aryaka can be configured to bypass the TCP interception of specific traffic. This can be implemented so that the TCP interception of traffic that is sourced from the IP address of an application like a port scanner. Contact Aryaka support to have this custom configuration applied.