TP-Link Archer A6(US)_V2 IPv6 firewall doesn't work

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.
12

TP-Link Archer A6(US)_V2 IPv6 firewall doesn't work

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.
15 Reply
Re:TP-Link Archer A6(US)_V2 IPv6 firewall doesn't work
2021-09-17 02:37:34

Bumping the topic to highlight the security vulnerability on PPPoe WAN6 IPv6:

Note: Since Archer A6 is using same firmware base as Archer C6, expect the same vulnerability for C6.

 

As I wrote before, port 22 (SSH) and port 53 (DNS) of the router itself are shown as "open" on IPv6.

Everything is fine on IPv4.

Servers with port 22 open are prone to brute-force attacks, now that is a risk no one willing to take.

Complete router takeover is possible risk.

To begin with, this port 22 shouldn't be visible or made available at WAN side.

DNS port 53 --> To be honest, this is an open vector for botnet DNS amplification attack if bad actor is able to abuse it.

I don't want my ISP or some organization to file a legal complaint on me if my device is being used for DDOS or proxy.

 

@Kevin_Z  , could you create a ticket for this A6/C6 security vulnerability? I believe my previously created tickets had been "cleared".

This time, the focus is getting/setting a proper IPv6 firewall rules for A6/C6 PPPoE WAN6 IPv6.

I believe a new firmware will be necessary.

 

 

  1  
  1  
#12
Options
Re:TP-Link Archer A6(US)_V2 IPv6 firewall doesn't work
2021-09-17 03:01:11

@JohnLai 

 

Created and sent, please confirm.

  0  
  0  
#13
Options
Re:TP-Link Archer A6(US)_V2 IPv6 firewall doesn't work
2021-09-17 10:36:33
Confirmed, I had received the ticket number. Thanks @Kevin_Z
  0  
  0  
#14
Options
Re:TP-Link Archer A6(US)_V2 IPv6 firewall doesn't work
2021-10-29 13:39:05

@JohnLai Hi, have you ever found a way to turn on the IPv6 SPI Firewall?

  0  
  0  
#15
Options
Re:TP-Link Archer A6(US)_V2 IPv6 firewall doesn't work
2022-03-30 08:54:20

Have A7 and hitting same thing.

 

SPI on, inbound IPv6 from the internet are not blocked. how do i enable blocking and only allow

whitelist inbound ipv6 to specific ports/addrs behind my router?

  0  
  0  
#16
Options