Firewall - Hundreds of ports open

Post new topic   Reply to topic    DD-WRT Forum Index -> Advanced Networking
Author Message
markwest
DD-WRT Novice


Joined: 10 Jun 2017
Posts: 2

PostPosted: Sat Jun 10, 2017 13:07    Post subject: Firewall - Hundreds of ports open Reply with quote
According to the GRC scan, I have a huge number of open ports:



I have the SPI firewall enabled. Why do I have so many open ports?
Sponsor
ATHF
DD-WRT Guru


Joined: 14 Dec 2015
Posts: 774
Location: 127.0.0.1

PostPosted: Sun Jun 11, 2017 4:52    Post subject: Reply with quote
Would help if you provided more information, what type of ISP you have, modem model, router model, DD-WRT version, and what is your network setup like?
_________________
Tutorial for flashing WRT series
WRT Installation,Upgrade & Basic Setup–Cliff Notes
r52242: WRT3200ACM, WRT1200ACv1 & 1 Velop in bridge mode(IoT subnet), r52242 WRT1900ACv1 AP
Velop:2 WHW0101, RE6500, RE9000(AP)
Spectrum - 1000/50
SysLog Watcher 5, New security Onion box coming soon, Fingboxes, PiHoles, NEMS, Cacti, rpisurv
markwest
DD-WRT Novice


Joined: 10 Jun 2017
Posts: 2

PostPosted: Sun Jun 11, 2017 21:01    Post subject: Reply with quote
ATHF wrote:
Would help if you provided more information, what type of ISP you have, modem model, router model, DD-WRT version, and what is your network setup like?


ISP: Sprint
Modem: Sierra EM7455
DDWrt: b21676 on a Linksys E1200
Second Router is a Netgear WNDR4300 running OpenWrt

My modem goes into the Netgear Router, then LAN from that goes into the WAN of DDWrt router, which all my other devices then connect to.
Alozaros
DD-WRT Guru


Joined: 16 Nov 2015
Posts: 6436
Location: UK, London, just across the river..

PostPosted: Mon Jun 12, 2017 20:19    Post subject: Reply with quote
first... ftp://ftp.dd-wrt.com/betas/2017/06-01-2017-r32170/broadcom_K26/
i ll rather try a newer build, on E1200

as well d0ug said instead ov chain Lan to Wan you can use it
as a WAP/Switch mode or just a switch Lan to Lan
https://www.dd-wrt.com/wiki/index.php/Wireless_Access_Point

do you run any scripts or special settings on that e1200 as well on Netgear ?? With that many ports open you might need to check for malware too..

_________________
Atheros
TP-Link WR740Nv1 ---DD-WRT 55630 WAP
TP-Link WR1043NDv2 -DD-WRT 55723 Gateway/DoT,Forced DNS,Ad-Block,Firewall,x4VLAN,VPN
TP-Link WR1043NDv2 -Gargoyle OS 1.15.x AP,DNS,QoS,Quotas
Qualcomm-Atheros
Netgear XR500 --DD-WRT 55779 Gateway/DoH,Forced DNS,AP Isolation,4VLAN,Ad-Block,Firewall,Vanilla
Netgear R7800 --DD-WRT 55819 Gateway/DoT,AD-Block,Forced DNS,AP&Net Isolation,x3VLAN,Firewall,Vanilla
Netgear R9000 --DD-WRT 55779 Gateway/DoT,AD-Block,AP Isolation,Firewall,Forced DNS,x2VLAN,Vanilla
Broadcom
Netgear R7000 --DD-WRT 55460 Gateway/SmartDNS/DoH,AD-Block,Firewall,Forced DNS,x3VLAN,VPN
NOT USING 5Ghz ANYWHERE
------------------------------------------------------
Stubby DNS over TLS I DNSCrypt v2 by mac913
hubermania
DD-WRT User


Joined: 24 Aug 2012
Posts: 223

PostPosted: Tue Jun 13, 2017 21:57    Post subject: Reply with quote
Shocked Yowza it's like your router has termites.

Make sure the UPnP Service is disabled on the NAT/QoS->UPnP tab. That'll take away your LAN clients' port opening superpowers.

_________________
[Broadcom] Asus rt-ac66u r35531 ('66 should only be factory reset through the DD UI)
Fix RT-AC66U "wl1 [2.4 GHz TurboQAM]". DD-WRT failsafe UI @ http|https://169.254.255.1/
Display posts from previous:    Page 1 of 1
Post new topic   Reply to topic    DD-WRT Forum Index -> Advanced Networking All times are GMT

Navigation

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You cannot download files in this forum