What's new

[RT-AC88U] NAT Passthrough Panel

  • SNBForums Code of Conduct

    SNBForums is a community for everyone, no matter what their level of experience.

    Please be tolerant and patient of others, especially newcomers. We are all here to share and learn!

    The rules are simple: Be patient, be nice, be helpful or be gone!

AntonK

Very Senior Member
Hi,

Is it best router security practice to 'disable' every one of these settings if none of them are being used?

Thanks,
Anton
 

Attachments

  • Clipboard01.jpg
    Clipboard01.jpg
    38 KB · Views: 554
I wouldn't say it's best practice, rather maybe configuration streamlining. Really, these are just additional features of the NAT implementation. What you allow and don't allow via NAT can be controlled in other ways.

Disabling each one may reduce the kernel footprint a little, assuming it prevents the relevant modules from loading. It's always possible any module loaded could increase the chance of a local vulnerability as well, in a multiuser environment.

If you see a performance improvement by disabling them and you definitely don't need them then I'd say go for it. For the most part though, having to re-enable these options when you do need them is going to be a pita.



Sent from my MI 5 using Tapatalk
 
In Asus's stock firmware case, disabling also means they add a series of firewall rules to explicitely drop traffic on the associated ports, which can lead to hard-to-track issues down the road (for instance, blocking IPSEC will prevent some VoIP services from working properly).
 
In Asus's stock firmware case, disabling also means they add a series of firewall rules to explicitely drop traffic on the associated ports, which can lead to hard-to-track issues down the road (for instance, blocking IPSEC will prevent some VoIP services from working properly).

I experienced exactly this and it confused the **** out of me for ages!!


Sent from my iPhone using Tapatalk
 
Thanks for the info!
 

Sign Up For SNBForums Daily Digest

Get an update of what's new every day delivered to your mailbox. Sign up here!
Top