
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-11-2022 09:39 AM
We were hoping to get some feedback on why a router would show ports open on the public facing interface when they are not running on the router? They are not specifically closed. Nat is configured in a manner that would not allow a connection through the router to an inside device. We checked the router versions and two separate routers running the same code, One shows the ports open and one does not. Also, we turned off smart-call home feature and still see the ports open.
Here are the ports:
25
110
143
Does anybody have any ideas or an explanation?
Solved! Go to Solution.
- Labels:
-
Other Network Security Topics
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-11-2022 05:28 PM
Put an ACL.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-12-2022 01:54 AM
Then there may be some Portforward or NAt in place that is where the port show as open.
So suggestion from outside always protect network using ACL, and scan again to confirm all ok
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-11-2022 10:02 AM
These are related to Mail , SMTP/ POP / IMAP ? what router is this ?
what is the outcome of scan
you can check on the router :
show ip socket
show ip tcp brief
show tcp brief

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-11-2022 01:57 PM
It is a branch router. Those ports are not listed in the show ip socket command or show tcp brief command.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-12-2022 01:54 AM
Then there may be some Portforward or NAt in place that is where the port show as open.
So suggestion from outside always protect network using ACL, and scan again to confirm all ok
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-11-2022 05:28 PM
Put an ACL.

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-15-2022 08:25 AM - edited 03-15-2022 08:26 AM
I am going to put an ACL in place just so the port shows closed to a scan. There is no NAT in place that would allow a connection from the outside. Thanks for the help!

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-31-2022 06:14 AM
Interestingly, I placed an ACL blocking port 25 to the outside interface IP address and the port still shows open on a scan. The access-list increments showing that it is denied. Any thoughts?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-31-2022 08:47 AM
post the ACL and interface config to understand
we would like to see the IP you scanning vs configured IP.
is that direct scanning?
