How to block ports (I want them to have "stealth" status)

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.
12

How to block ports (I want them to have "stealth" status)

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.
How to block ports (I want them to have "stealth" status)
How to block ports (I want them to have "stealth" status)
2013-06-23 16:06:18
Region : Others

Model : TD-W8961ND

Hardware Version : V3

Firmware Version : Latest

ISP : Various


Hello

When I use GRC's Shields Up! website and scan for open common ports, ports 135, 139 and 445 show up as being "closed" instead of "stealth".

How do I set up my router to keep these ports stealthy?

Thanks
  0      
  0      
#1
Options
15 Reply
Re:How to block ports (I want them to have "stealth" status)
2013-06-24 10:31:36
Ports 135, 139 and 445 are closed by default on the modem router.

"How do I set up my router to keep these ports stealthy?"
Not quite sure what you exactly want. Do you want to open these ports?
  0  
  0  
#2
Options
Re:How to block ports (I want them to have "stealth" status)
2013-06-29 15:26:09
On the GRC website it states the following:
[quote]Solicited TCP Packets: RECEIVED (FAILED) — As detailed in the port report below, one or more of your system's ports actively responded to our deliberate attempts to establish a connection. It is generally possible to increase your system's security by hiding it from the probes of potentially hostile hackers[/quote]

So I want to have my router hidden from the internet if somebody decides to run a port-scan to look for active IP's.
  0  
  0  
#3
Options
Re:How to block ports (I want them to have "stealth" status)
2013-06-29 15:27:12
Oh and port 7547 seems to be open on my router...how do I close it?
  0  
  0  
#4
Options
Re:How to block ports (I want them to have "stealth" status)
2013-07-01 16:53:20

Praeses wrote

Oh and port 7547 seems to be open on my router...how do I close it?

Well, it is quite weird. Are you still using GRC's Shields Up! website to test it and get this result?
  0  
  0  
#5
Options
Re:How to block ports (I want them to have "stealth" status)
2013-07-10 14:29:13
Sorry for taking so long to reply

It's still open when I use the internet through my router's gateway. If I connect with a PPPoE connection (bridged mode) from Windows it's closed, as I guess my OS's firewall then blocks it as it by-passes the firewall on the router. So it's definitely a problem on the router's side.
  0  
  0  
#6
Options
Re:How to block ports (I want them to have "stealth" status)
2013-07-11 14:33:54

Praeses wrote

Sorry for taking so long to reply

It's still open when I use the internet through my router's gateway. If I connect with a PPPoE connection (bridged mode) from Windows it's closed, as I guess my OS's firewall then blocks it as it by-passes the firewall on the router. So it's definitely a problem on the router's side.

Right, it seems that TP-Link needs to update the firmware to close Port 7547 on the modem.
I contacted with TP-LINK support before, and they told me that the modem could not hide the ports that had been opened. :(
And to further secure my modem, they suggested me turn on firewall and SPI on the modem.
  0  
  0  
#7
Options
Re:How to block ports (I want them to have "stealth" status)
2013-07-11 16:35:51

Snowy wrote

Right, it seems that TP-Link needs to update the firmware to close Port 7547 on the modem.
I contacted with TP-LINK support before, and they told me that the modem could not hide the ports that had been opened. :(
And to further secure my modem, they suggested me turn on firewall and SPI on the modem.


Those are turned on on my router.

Do they read these forums?
  0  
  0  
#8
Options
Re:How to block ports (I want them to have "stealth" status)
2013-07-12 15:11:20
Hi, all.
I find out a new beta firmware for TD-W8961ND_ V3 on the TP-Link website. Maybe Port 7547 can be closed by firmware update.
Here is the download link of the beta firmware:
http://www.tp-link.com/resources/software/TD-W8961ND_v3_Beta_130705.zip

And you can follow this FAQ to upgrade the firmware.
http://www.tp-link.com/en/article/?faqid=107
  0  
  0  
#9
Options
Re:How to block ports (I want them to have "stealth" status)
2013-07-12 15:42:07

alisa wrote

Hi, all.
I find out a new beta firmware for TD-W8961ND_ V3 on the TP-Link website. Maybe Port 7547 can be closed by firmware update.
Here is the download link of the beta firmware:
http://www.tp-link.com/resources/software/TD-W8961ND_v3_Beta_130705.zip

And you can follow this FAQ to upgrade the firmware.
http://www.tp-link.com/en/article/?faqid=107


Thanks!

Here's the changelog:

This BETA firmware of TD-W8961ND v3 has solved these following problems:

1:I can't use the bonjour application like airprint and WiFi sync, when iPhone is connected to TD-W8961ND v3.

2:My PC can't acquire an IP address from an AP which is connected to TD-W8961ND v3 in universal repeater mode.

3:The DHCP lease of IOS device offered by TD-W8961ND v3 is too long.

4:My PC can't go to Internet if it is originally connected to an AP, and now it is connected to TD-W8961ND v3.

5:The port of 7547 is still open even when CWMP function is disabled.

EDIT: I can confirm that 7547 now has "STEALTH" status!!
  0  
  0  
#10
Options
Re:How to block ports (I want them to have "stealth" status)
2013-07-29 12:38:37

Praeses wrote

Thanks!

Here's the changelog:

This BETA firmware of TD-W8961ND v3 has solved these following problems:

1:I can't use the bonjour application like airprint and WiFi sync, when iPhone is connected to TD-W8961ND v3.

2:My PC can't acquire an IP address from an AP which is connected to TD-W8961ND v3 in universal repeater mode.

3:The DHCP lease of IOS device offered by TD-W8961ND v3 is too long.

4:My PC can't go to Internet if it is originally connected to an AP, and now it is connected to TD-W8961ND v3.

5:The port of 7547 is still open even when CWMP function is disabled.

EDIT: I can confirm that 7547 now has "STEALTH" status!!


what is this port and is it worth upgrading to a BETA firmware just to hide it? I use a iphone, android tablet, ps3 and pc, all wireless, and would not want to have connection issues with this router... outside of the existing issues where all other devices can lose connection if something is hogging the bandwidth, like my ps3 running netflix or if my pc is downloading something quite large.

my firmware is Firmware Version: 3.0.0 Build 120524 Rel.05221

edit: cant upgrade my fw anyways, there is no fw page in the router (the menu text is there but no page, just:


Error Message:

ERROR: FAIL TO UPDATE DUE TO... ERROR: FAIL TO UPDATE DUE TO...
  0  
  0  
#11
Options