pfSense Support Subscription

Author Topic: Ports open to internet, which I did not configure  (Read 358 times)

0 Members and 1 Guest are viewing this topic.

Offline nubletizer

  • Newbie
  • *
  • Posts: 4
  • Karma: +0/-0
    • View Profile
Ports open to internet, which I did not configure
« on: April 20, 2017, 09:10:56 am »
Hi all,

I needed to open a few ports and ran an nmap scan from the internet to test, all good, however I found that the below ports were also opened, which I had never configured. All ports from the internet were previously blocked, or so I had thought.

21
554
1723
53

I ran another scan 10 minutes later and the concerning ports were no longer open. Is there any rational explanation for this? How would you guys investigate? It's quite concerning. I'll post up my firewall configs tomorrow.

Offline johnpoz

  • Hero Member
  • *****
  • Posts: 13113
  • Karma: +1149/-149
  • Not a pfSense employee, they cannot fire me...
    • View Profile
Re: Ports open to internet, which I did not configure
« Reply #1 on: April 20, 2017, 09:40:42 am »
And pfsense clearly has no ftp server out of the box, so how would 21 be open to it.  Are you forwarding that port?

Out of the box pfsense is block ALL inbound to its wan port.  So if your seeing stuff open, you opened them or forwarded them or your seeing the device in front of pfsense.  What is the wan of your pfsense plugged into?  Does it have a public IP on its wan or a rfc1918 address?  If rfc1918, out of the box any traffic to rfc1918 would be blocked as well.

Post up your wan firewall rules, and did you put any rules on your floating tab?
- An intelligent man is sometimes forced to be drunk to spend time with his fools.
- If I have helped you and want to help back, https://www.freebsdfoundation.org/donate/
- Please don't PM me for personal help, info you don't want public sure. Link to thread you would like me to look at ok, etc.
1x SG-2440 2.3.4_p1 (work)
1x 2.4.0-BETA Aug 16 07:00:51 VM running on esxi 6.5 (home)

Offline Gertjan

  • Hero Member
  • *****
  • Posts: 1860
  • Karma: +155/-6
    • View Profile
Re: Ports open to internet, which I did not configure
« Reply #2 on: April 20, 2017, 05:30:50 pm »
Another question : how are you connected to the net ? or : what is placed in front of your pfSense box ? Some ISP router ?

Offline NOYB

  • Hero Member
  • *****
  • Posts: 1726
  • Karma: +159/-273
    • View Profile
Re: Ports open to internet, which I did not configure
« Reply #3 on: April 20, 2017, 06:01:40 pm »
Is there any rational explanation for this?

Typo.  You scanned some else.

Offline nubletizer

  • Newbie
  • *
  • Posts: 4
  • Karma: +0/-0
    • View Profile
Re: Ports open to internet, which I did not configure
« Reply #4 on: April 21, 2017, 06:03:13 am »
I have 2 separate NICs. One dedicated for WAN. The other NIC has three ports, one for management, one primary network and one guest network. WAN port is a direct DHCP internet connection.

Here's some config screenshots

http://www.openscreenshot.com/B1MLNwDAg
http://www.openscreenshot.com/ByCPEDPAe
http://www.openscreenshot.com/HkIFNPDAl
http://www.openscreenshot.com/SkC_HDD0g
http://www.openscreenshot.com/B13prDDAl
http://www.openscreenshot.com/S1vCBvv0e
http://www.openscreenshot.com/HJGJ8PvCx

I definitely scanned the right IP. They're now appearing closed though.