04-14-2019 08:47 PM
I am playing around with Snort on a router behind an RV320 router. Funny thing is that it is getting port scanned from IPs from out on the WAN.
So the big question is, why are port scans getting through the RV320 firewall?
Everything is up to date...
04-14-2019 08:49 PM
04-14-2019 09:21 PM
The alert only indicates it was a scan of UDP ports. And it lists the source, which are internet IPs not lan IPs.
04-15-2019 05:02 AM
04-15-2019 07:39 PM
There is no forwarding set up on this router. There are no ports open.
Tried one of those firewall testers and it said everything was ok. Makes no sense.
Have no idea how this traffic is getting in. Could it be leaking though someone on a VPN or an IOT device.
No real tweaks besides a couple of vlans.
04-15-2019 09:22 PM
Update:
Did more investigating with some other tools. I always noticed with snort that there would be a couple of scans and then nothing for a long while. What I just noticed with another tool is that when something new comes on the LAN there is a flood from the WAN right after that.
From what I can gather is that for some reason the firewall goes down, for a short while, when something connects to the LAN (VLAN to be exact).
04-16-2019 04:45 AM
@Scott Frank hello,
You can user a logs to know what address was sending a lot of packets to your wan interface on your firewall and try block it. To do same for the lan you can use a wireshark to mitigate what device do it.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide