What's new
  • SNBForums Code of Conduct

    SNBForums is a community for everyone, no matter what their level of experience.

    Please be tolerant and patient of others, especially newcomers. We are all here to share and learn!

    The rules are simple: Be patient, be nice, be helpful or be gone!

[Security] SSH port opened to WAN even though "Enable SSH" is set to "LAN only"

ppfoong

Regular Contributor
Today I run a port scan to my Asus RT-AX86U router running firmware 3004.388.9_2.

To my surprise, I discovered that my SSH port is opened to WAN even though I have set it to "LAN only". Meaning, the "LAN only" setting is not in action at all!

When I try SSH to my external IP address, the connection established, and I am able to login using my login and password.

1758969178850.png


Please try SSH to your external IP address and check if this issue also happen to you as well.
 
When I try SSH to my external IP address, the connection established, and I am able to login using my login and password.

How are you testing this? You need to do the test from the internet, not from inside your LAN.

If you try to connect to your WAN IP from inside your LAN it will work. This is to be expected. However, you will not be able to connect to that IP from the internet because the router's firewall will block it. This is all by design.

Go to the following site to perform the test from the internet.
 
I see a similar issue. This is using nmap from inside the lan. Even though the setting is turned off per @ppfoong, it still shows up, but not reachable from the outside. It's just an annoyance, but it makes my heart skip a beat every time I see it, and wonder if something is tunneling through the firewall. This happened somewhere along the way, because a few firmware versions back, it was reporting 0 open ports on WAN0.

1758976592406.png
 
Last edited:

Similar threads

Support SNBForums w/ Amazon

If you'd like to support SNBForums, just use this link and buy anything on Amazon. Thanks!

Sign Up For SNBForums Daily Digest

Get an update of what's new every day delivered to your mailbox. Sign up here!
Back
Top