TP-Link Archer A6(US)_V2 IPv6 firewall doesn't work

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.
12

TP-Link Archer A6(US)_V2 IPv6 firewall doesn't work

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.
15 Reply
Re:TP-Link Archer A6(US)_V2 IPv6 firewall doesn't work
2021-09-17 02:37:34

Bumping the topic to highlight the security vulnerability on PPPoe WAN6 IPv6:

Note: Since Archer A6 is using same firmware base as Archer C6, expect the same vulnerability for C6.

 

As I wrote before, port 22 (SSH) and port 53 (DNS) of the router itself are shown as "open" on IPv6.

Everything is fine on IPv4.

Servers with port 22 open are prone to brute-force attacks, now that is a risk no one willing to take.

Complete router takeover is possible risk.

To begin with, this port 22 shouldn't be visible or made available at WAN side.

DNS port 53 --> To be honest, this is an open vector for botnet DNS amplification attack if bad actor is able to abuse it.

I don't want my ISP or some organization to file a legal complaint on me if my device is being used for DDOS or proxy.

 

@Kevin_Z  , could you create a ticket for this A6/C6 security vulnerability? I believe my previously created tickets had been "cleared".

This time, the focus is getting/setting a proper IPv6 firewall rules for A6/C6 PPPoE WAN6 IPv6.

I believe a new firmware will be necessary.

 

 

  1  
  1  
#12
Options
Re:TP-Link Archer A6(US)_V2 IPv6 firewall doesn't work
2021-09-17 03:01:11

@JohnLai 

 

Created and sent, please confirm.

Nice to Meet You in Our TP-Link Community. Check Out the Latest Posts: Connect TP-Link Archer BE550 to Germany's DS-Lite (Dual Stack Lite) Internet via WAN Archer GE550 - BE9300 Tri-Band Wi-Fi 7 Gaming Router Archer BE800 New Firmware Added Support for EasyMesh in AP Mode, DoH&DoT, and 3-Band MLO Connection Archer AX90 New Firmware Added Support for EasyMesh and Ethernet Backhaul If you found a post or response helpful, please click Helpful (arrow pointing upward icon). If you are the author of a topic, remember to mark a helpful reply as the "Recommended Solution" (star icon) so that others can benefit from it.
  0  
  0  
#13
Options
Re:TP-Link Archer A6(US)_V2 IPv6 firewall doesn't work
2021-09-17 10:36:33
Confirmed, I had received the ticket number. Thanks @Kevin_Z
  0  
  0  
#14
Options
Re:TP-Link Archer A6(US)_V2 IPv6 firewall doesn't work
2021-10-29 13:39:05

@JohnLai Hi, have you ever found a way to turn on the IPv6 SPI Firewall?

  0  
  0  
#15
Options
Re:TP-Link Archer A6(US)_V2 IPv6 firewall doesn't work
2022-03-30 08:54:20

Have A7 and hitting same thing.

 

SPI on, inbound IPv6 from the internet are not blocked. how do i enable blocking and only allow

whitelist inbound ipv6 to specific ports/addrs behind my router?

  0  
  0  
#16
Options