problem with firewall?

Post new topic   Reply to topic    DD-WRT Forum Index -> Marvell MVEBU based Hardware (WRT1900AC etc.)
Author Message
johnnyNobody999
DD-WRT Guru


Joined: 10 Jan 2014
Posts: 504

PostPosted: Fri Feb 14, 2020 0:07    Post subject: problem with firewall? Reply with quote
I keep getting a lot of syslog messages like this even though I don't have the router configured for telnet access from the WAN. Why?

telnetd[1341]: telnetd : client 83.252.11.216 is blocked, terminate connection
Sponsor
johnnyNobody999
DD-WRT Guru


Joined: 10 Jan 2014
Posts: 504

PostPosted: Fri Feb 14, 2020 0:12    Post subject: Reply with quote
Hmm, after unchecking Limit Telnet Access (WAN), a port scan shows that the port is blocked now. I don't understand why that would open port 23 to the internet.
johnnyNobody999
DD-WRT Guru


Joined: 10 Jan 2014
Posts: 504

PostPosted: Fri Feb 14, 2020 18:06    Post subject: Reply with quote
I should've mentioned that remote administration on the Administration->Management->Telnet Management isn't enabled. So, why is this Security-Firewall->Impede WAN DoS/Bruteforce->Limit Telnet Access setting opening the firewall for telnetd?
zakaron
DD-WRT User


Joined: 03 Jun 2016
Posts: 91

PostPosted: Sat Feb 15, 2020 18:25    Post subject: Reply with quote
I can't tell you why you are seeing that behavoir, but I only offer a suggestion that I've been using for years. I use FWBuilder to construct my own firewall rules that is pushed out to my WRT1200ac. I know exactly what is allowed in & out this way. Unless you know iptables extremely well, this is a great tool to construct a comprehensive ruleset.
ho1Aetoo
DD-WRT Guru


Joined: 19 Feb 2019
Posts: 2977
Location: Germany

PostPosted: Sat Feb 15, 2020 20:17    Post subject: Reply with quote
@johnnyNobody999

Rolling Eyes

the option simply limits access to services such as shh, telnet, etc

why the hell do you activate the function if you have not activated shh, telnet remote access?
johnnyNobody999
DD-WRT Guru


Joined: 10 Jan 2014
Posts: 504

PostPosted: Sat Feb 15, 2020 21:06    Post subject: Reply with quote
ho1Aetoo wrote:
@johnnyNobody999

Rolling Eyes

the option simply limits access to services such as shh, telnet, etc

why the hell do you activate the function if you have not activated shh, telnet remote access?


First, don't make comments that can start a flame war. Second, your last comment doesn't address my issue. Third, there are times when I open the ssh port when I plan to travel. Fourth, those options opens the port(s) when they shouldn't which makes it a serious security concern.
ho1Aetoo
DD-WRT Guru


Joined: 19 Feb 2019
Posts: 2977
Location: Germany

PostPosted: Sat Feb 15, 2020 21:16    Post subject: Reply with quote
as i said, the option is intended for open ports ...

and not if no remote access is set up anyway
Display posts from previous:    Page 1 of 1
Post new topic   Reply to topic    DD-WRT Forum Index -> Marvell MVEBU based Hardware (WRT1900AC etc.) All times are GMT

Navigation

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You cannot download files in this forum