cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
898
Views
0
Helpful
6
Replies

RV320 letting port scans through firewall...

Scott Frank
Level 1
Level 1

I am playing around with Snort on a router behind an RV320 router.  Funny thing is that it is getting port scanned from IPs from out on the WAN.

 

So the big question is, why are port scans getting through the RV320 firewall?

 

Everything is up to date...

6 Replies 6

Jaderson Pessoa
VIP Alumni
VIP Alumni
Hello,

What port you are getting from your firewall?
Jaderson Pessoa
*** Rate All Helpful Responses ***

The alert only indicates it was a scan of UDP ports.  And it lists the source, which are internet IPs not lan IPs.

scan from out side its normally, all the time there are someone that trying access ours data, but you need know what kind of services are allowed to external side.
Jaderson Pessoa
*** Rate All Helpful Responses ***

There is no forwarding set up on this router.  There are no ports open.

 

Tried one of those firewall testers and it said everything was ok.  Makes no sense.

 

Have no idea how this traffic is getting in.  Could it be leaking though someone on a VPN or an IOT device.

 

No real tweaks besides a couple of vlans.

Update:

 

Did more investigating with some other tools.  I always noticed with snort that there would be a couple of scans and then nothing for a long while.  What I just noticed with another tool is that when something new comes on the LAN there is a flood from the WAN right after that. 

 

From what I can gather is that for some reason the firewall goes down, for a short while, when something connects to the LAN (VLAN to be exact).

@Scott Frank  hello,

 

 

You can user a logs to know what address was sending a lot of packets to your wan interface on your firewall and try block it. To do same for the lan you can use a wireshark to mitigate what device do it.

Jaderson Pessoa
*** Rate All Helpful Responses ***