What's new
  • SNBForums Code of Conduct

    SNBForums is a community for everyone, no matter what their level of experience.

    Please be tolerant and patient of others, especially newcomers. We are all here to share and learn!

    The rules are simple: Be patient, be nice, be helpful or be gone!

Default open ports on RT-AC68U with Merlin FW (3.0.0.4_374.39_0)

Kreeture

Occasional Visitor
Hi all,

First off thanks to Merlin for the great work both with the firmware and supporting people in these forums.
I appreciate the following issues are not merlins doing :)

I searched and found some info but no conclusive answers so here we go...

I have the latest merlin fw on an RT-AC68U (3.0.0.4_374.39_0) and have ensured UPnP, FTP and SMB services are all disabled. Also there is no USB disks connected.
The port forwarding is enabled as I need access to some ports on my network.

However performing a scan with shields up the ports 0, 21, 22 and 445 appear closed and not stealth as I would expect.

445 I assume is something to do with the SMB service but I don't have this enabled in any way. How can I force this to stealth and why is it defaulting to open?

21 & 22 are the ftp ports and in the port forwarding router config page there is an entry for these ports, however I don't want them open. Is there anyway to disable the forwarding of these?
I tried clearing the field but it was not a valid input.
Merlin would it be possible to just disable the FTP ports if this field is empty?

As for port 0, no idea, anyone?

I guess these ports could be forced to stealth with custom firewall rules but is there an easy way to enter these via the web guy?

One more thing, in the system log -> port forward page there is no indication these ports are open, why is this?

Thanks for any help.
 
Last edited:
When ports appear as closed instead of stealth, it's often because your ISP is actively rejecting connections on these ports. There's nothing you can do about it, and it's not something to worry about either. A closed port is just as secure as a stealth port.

Port 0 does not exist - valid ports are from 1 to 65535.
 
I am pretty sure this in not my ISP as I have had all ports stealthed previously.
I realise a closed port isn't a real security risk but I would rather have them stealthed in case a service defaults to one of the ports and hence opens it up.

The FTP ports are definitely affected by the nat, in the WAN port forwarding options if I change the 'FTP server port' from the 2021 default it will then open that port and stealth 2021.
It would be nice to be able to correctly stealth this port but it seems in the web ui there is no way to do this.

I am not so familiar with the internals of firewalls, but is it somehow adaptive? Shields up seems to give different results on each scan :/
 
I am pretty sure this in not my ISP as I have had all ports stealthed previously.
I realise a closed port isn't a real security risk but I would rather have them stealthed in case a service defaults to one of the ports and hence opens it up.

The FTP ports are definitely affected by the nat, in the WAN port forwarding options if I change the 'FTP server port' from the 2021 default it will then open that port and stealth 2021.
It would be nice to be able to correctly stealth this port but it seems in the web ui there is no way to do this.

I am not so familiar with the internals of firewalls, but is it somehow adaptive? Shields up seems to give different results on each scan :/

The link/thread below gives the history of previous problem and somewhat explains why the AC68 and AC56 show closed on those ports instead of steath after Merlin patched it in .39
Merlin said Asus is working on a fix/update for stock firmware. I would imagine you will see stealth instead of closed as soon as they release the fix/update.

If your other router shows stealth, then your ISP is probably not blocking those ports.

http://forums.smallnetbuilder.com/showthread.php?t=14660
 

Support SNBForums w/ Amazon

If you'd like to support SNBForums, just use this link and buy anything on Amazon. Thanks!

Sign Up For SNBForums Daily Digest

Get an update of what's new every day delivered to your mailbox. Sign up here!
Back
Top