EA2700 WAN PORT open to the world by default?

I just noticed last night that my EA2700 router was accessible on the WAN port, from the Internet, on ports 80 and 53. I am running router firmware 1.0.14 and the update utility reports that there is no newer version.
Remote management is NOT enabled (it defaults to port 8080 anyway) and I enabled and disabled it for good measure. Rebooted a few times, too.
I then enabled and disabled the regular admin interface on HTTPS and turned off HTTP. That enabled the admin interface on port 443, but still left it enabled on port 80. And now both port 80 and 443 were accessible outside the firewall! And now I couldn't turn off port 443!
I disabled UPnP and rebooted and still the ports were open to the Internet.
Needless to say, I was pretty horrified by this discovery.
I only leave one port forwarded, port 22, to SSH on an internal box. That is the only hole through my firewall I ever expect to see.
As a fix for this problem, I added three new port forwards on port 80, port 53 and port 443, and mapped them all to a random port on an unused IP on my internal network. THIS and ONLY this finally made ports 80, 53, and 443 inaccessible from the Internet at large.
What's going on here? It seems hard to believe that EVERY EA2700 device would have this issue or this would've come out long ago. Any ideas?

https://superevr.com/blog/2013/dont-use-linksys-routers/

Similar Messages

  • EA2700 WAN Port Speed

    I just bought an EA2700. The diagnostic says that the WAN port speed is 1 Gigabit. Speedtest however reveals max 85 Mbit throughput which makes me believe that is just Fast Ethernet (100 Mbit). My internet provider delivers 120 Mbit down speed and I would like to get full speed, what is wrong?

    This article shows different ways to retrieve your wireless password, raconerz.

  • Will any mail apps open to the inbox by default?

    I have been using computers for decades...and have had my iPhone for a few years now. It was only a few days ago that I got my first iPad and was surprised by the "feature" that all of the mail apps seem offer...
    I am talking about opening the app to the last email you were looking at. I tried a few different apps and they all seem to offer the same thing.
    Why does it seem to be an iPad thing to make you go to your inbox instead of having it be the first thing you see?
    Can anyone direct me to an app for the iPad that when I open it, I will see my inbox?
    Maybe it's just me but I don't want the contents of an email being displayed on my screen until I choose...who knows who will be looking over my shoulder when the app is opened.
    Thanks in advance for any help you can send my way.
    Scott

    This answer does not help me at all.
    It does not address my initial question...not even a little bit.
    Me mentioning someone looking over my shoulder was just an example.
    The point is, I want an app that opens by default directly to the inbox.
    If you have anything useful to contribute, please do.
    Scott

  • Which port is the WAN port?

    which port is the WAN port?

    The WAN port will have a "world" icon, which looks more like a circle of dots.
    The  LAN port(s) will have opposing arrows....something like this <->

  • Save running-config out WAN port?

    Hi all.  As I look at the thread headings fo rthe other posts I'm struck by how simple my request must seem I hope this is an easy one! 
    Using 891W routers, I would like to be able to save the running-config out the WAN port (gig0).  The most common scenario is that I am SSH'd into a router, but the LAN doesn't have a TFTP server nor is it ideal to put one in there.  So I want to save the routers config to myself here somehow
    The site that has the rotuer I want to save from is connected via L2L IPSec VPN to head office, and through that tunnel I can ping, RDP, whatever.  However, I cannot save the running-config even to a machine on that LAN that has a TFTP server.  It just seems TFTP is blocked by default from sending anything out on the WAN port.  I've enabled all traffic between these two routers in the ZBFW, but still it doesn't work.  I think blocking TFTP from sending out the WAN port might be hard-coded into the IOS or something.
    Anybody have thoughts on this?  Thank you. 

    Hi Julio,
    Self zones in use are only the OUT-SELF.  No SELF-OUT.  The L2L VPN works now.  The ZBFW setup to allow the VPN to work is one ACL within a 2nd class map inside the OUTSIDE-INSIDE policy map allowing all traffic from one LAN network to the other and this is set on both routers (inversing the network IDs of course).  Also to allow the VPN tunnel itself to form, there is an ACL in a 2nd class map on within the OUT-SELF policy map, which allows traffic between the two rouer WAN port IP's (allowing port 500, non500, and all esp). 
    But what confuses me is this.  If I edit that ACL governing the two VPN endpoints, so that instead of just port 500 and such I also say to permit ip any any, I can for example SSH from one router CLI to the other router CLI, whereas without adding this entry to the ACL, I cannot so I know failry surely that this perit ip any any opens any traffic between the two routers. 
    But this is likely where my lack of understanding of VPN comes in.  I imagine I am not actually sending TFTP files through the VPN then...in effect I'm trying to send a TFTP file from one router, to the LAN side of the other router.  Perhaps not possible? 
    I'm actally confusing myself here the more I type.  I'll leave this post for now, read Alain's and will reply there. 

  • P13N Server and App Server on separate systems - strange ports opened

    Hi -
              We have a configuration using WebLogic Personalization Server 3.1.1 on one
              server and WebLogic Application Server 5.1 w/Service Pack 6 on another
              server. What we've seen with our firewall configuration is that it appears
              there are high-number random ports opened occasionally from the App Server
              to the P13N Server, which d not appear to be related to connection attempts
              (ex: port 42100). The only communication that we know should be happening
              between the two systems are T3-based JNDI lookups, LDAP lookup/update
              requests, and SQL queries. My questions, then, are as follows:
              1) In handling JNDI requests, are there any callbacks that can occur between
              the two servers in this configuration on a different port?
              2) When separating the P13N Server and App Server, are there any "private"
              ports opened between the two systems for management? As far as I know, the
              App Server should simply view the P13N Server as another client, but the
              firewall log would indicate that something is going on related to this.
              If anyone has a similar config and can provide some info related to
              potentially unseen port connections, please let me know. Thanks in advance!
              Andy
              [email protected]
              

    Haakon,
    I think the BPEL forum is the better source to ask
    BPEL
    Frank

  • VPN - FireWall : do i need to keep port open ?

    hi,
    when i try to turn off AFP port in the firewall settings, i can't connect to the AFP server anymore even when i have a VPN session open.
    i was under the impression that connections going trough the VPN would not need to have their ports open in the firewall.
    is this normal or some setting are missing ?
    thanx for the help

    Sounds like you are not connecting to the AFP server through the VPN. Easy way to test this is connect VPN, mount a volume, and kill the VPN connection - if you still can access the volume, you are not connecting through the VPN.
    I'm assuming you are home or whatever and tell your VPN to connect, it does it's thing and shows you are connected, then you 'Connect to Server'. The AFP server (name or IP) you use needs to be a name or IP within the VPN.
    If your VPN is directly to the server 'myserver.com' which is also is your AFP server, you need to 'Connect' to the private net ip of your server that is in the same subnet you VPN server is assigning connections to.

  • Problem with COM port opening

    I made an application using COM port to dialog with a microcontroleur and i have some troubles with the opening of the port. i developed it under window XP pro and labview 6.1 and i have no problem when i launch my application on an XP PC having labview installed or on a window 98 PC without labview (just the runtime engine). But when i launch it on an XP pc with only the runtime engine, it seems to launch correctly but in fact, there is a problem with the COM port opening. The menu allowing to chose the port number is inactive and has no effect, like if the software wouldn't recognize the material port on the PC. And consequently, nothing happens when the dialog should start.
    Thank tou for your precious help
    Julien LEGRAND
    French Natio
    nal Institute for Sea Reseach

    Is the VISA run-time engine installed? I don't understand why it would work on the win98 machine unless you have an older installation of it there.

  • WAN Port Unplugged Issues

    I am having cronic issues with the WAN port reporting that it is unplugged. The Time Capsule LED is flashing amber when this happens. To resolve the issue I simply unplug and replug the WAN port cable and it comes back up. I know the issue is not the Cable Modem as I have connected two other non-Apple routers and I never have this issue. I have enabled debugging level of syslogs and nothing unusual pops up.
    Has anyone else run into this issue? I have the AirPort Utility installed on a MBP and a Windows 7 system.

    dedwards wrote:
    I am having cronic issues with the WAN port reporting that it is unplugged. The Time Capsule LED is flashing amber when this happens.
    When that happens do you see a tiny green light next to the WAN port socket on the Time Capsule?
    You might try reversing that Ethernet cable end-for-end or trying a different cable.

  • WAN port configuration SA520w

    We switched to another internet provider and have problem with our SA520w and a slow WAN connection on av fibre connection.
    We have confirmed that we need to set/ force the WAN port interface on the router to use 10base-t (Full duplex) in order to get maxium speed from our Internet provider. Is there any solution force the router to use that settings as I cant find that alternative on the port setting page in router configuration?
    Latest firmware installed
    Thanks

    Hi,
    You can change speed and duplex settings at Networking->Port Management -> Port Management.
    Thanks,
    Biraja

  • Activity logging for WAN port on WRT1900ac

    Hi everybody, I'm looking to monitor the activity on the WAN port. When the WAN goes on/off line, to find out when I loose connection with my internet provider. I know where to monitor the use of the ports being used, but I'm looking specific to the connects / disconnects on my WAN port towards my provider. Has anybody have suggestions?
    John

    What region are you located?
    Has a Factory Reset been performed?
    Was a Factory Reset performed before and after any firmware updates then set up from scratch?
    Internet Service Provider and Modem Configurations
    What ISP Service do you have? Cable or DSL?
    What ISP Modem Mfr. and model # do you have?
    Is ISP Modem/Service using Dynamic or Static WAN IP addressing?
    What ISP Modem service link speeds UP and Down do you have?
    Check cable between Modem and Router, swap out to be sure. Link>http://en.wikipedia.org/wiki/CAT6 is recommended.
    Check ISP MTU requirements, Cable is usually 1500, DSL is around 1492 down to 1472. Call the ISP and ask.
    http://kb.linksys.com/Linksys/ukp.aspx?vw=1&docid=88e63d78588142e6bb68e22d7faf2046_Configuring_the_M...
    I recommend that you have your ISP check the cabling going to the ISP modem, check signal levels going to the ISP modem. For cable Internet, RG-6 coaxial cable is needed, not RG-59. Check for t.v. line splitters and remove them as they can introduce noise on the line and lower the signal going to the ISP modem. Connecting to the ISP modem could result in a false positive as the signal to the modem could be just enough to that point then adding on a router, could see problems. Ensure modem is working well too. Bad modems are out there as well. The router operation is dependent upon getting good data flow from the ISP modem and the modem is dependent upon getting good signal from the ISP Service.
    Not sure if using the following will have information on WAN port activity:
    192.168.1.1\sysinfo.cgi

  • RV320 - using one WAN port

    What is the correct configuration for using one WAN port so that the router doesn't crash several times a day?
    Should WAN2 be left as address from IP ?
    Shoudl WAN2 be configured as static IP ?
    Should WAN2 interface be disabled?
    Should WAN2 be configured as DMZ and left as default 192.168.1.0?
    Should WAN2 be configured as DMZ and then disabled?
    It's definitely the router which is at fault, power cycling the fibre to copper converter dosen't fix the issue.
    Nor does swapping the FTC for a brand new one.
    Only a power cycle on the RV320, or a remote web interface reset if I'm unside the LAN, makes it work.
    Temporarily, then it crashes next day.

    I have the same settings, and the same up-to-date firmware.
    I see in the logs that the router incorrectly reports WAN2 as Up, then can't sync rate with it.
    Most of the time that failure is around the same time as the users report failure.
    But nothing is logged for WAN1 so it doesn't seem to be a physical failure in cabling, or the FTC converter feeding the router.
    2015-04-27, 10:33:35
    Kernel
    kernel: WAN [2] UP
    2015-04-27, 10:33:35
    Kernel
    kernel: [eth0] lanip=192.168.1.1, mask=255.255.255.0
    2015-04-27, 10:33:35
    Kernel
    kernel: ip[xxx.xxx.xx.xxx] mask[0.0.0.0]
    2015-04-27, 10:33:35
    Kernel
    kernel: ip[0.0.0.0] mask[0.0.0.0]
    2015-04-27, 10:33:36
    Kernel
    kernel: WAN [2] DOWN
    2015-04-27, 10:42:10
    Kernel
    kernel: WARNING: cant get external phy status
    2015-04-27, 10:42:11
    Kernel
    kernel: WARNING: no highest common denominator or auto-negotiation not complete
    2015-04-27, 10:42:11
    Kernel
    kernel: WARNING: no highest common denominator or auto-negotiation not complete
    2015-04-27, 10:58:01
    Kernel
    kernel: WARNING: no highest common denominator or auto-negotiation not complete
    2015-04-27, 10:58:02
    Kernel
    last message repeated 2 times
    2015-04-27, 10:58:02
    Kernel
    kernel: nk_bcm53115_sync_speeds_phy_to_mac(): sport[5], speed[0], duplex[0]
    2015-04-27, 10:58:03
    Kernel
    kernel: nk_bcm53115_sync_speeds_phy_to_mac(): sport[5], speed[1], duplex[2]

  • No internet access, wan port light does not glow solid

    Hello,
    I can set up a wireless network with my Airport Extreme but I can't connect to the Internet through it.
    The light above the wan port does not glow solid when a cable is attached between the base station and the cable modem.
    (Sometimes the Wan port light will glow solid for a few minutes but then it will go out.)
    I've tried several Ethernet cables but no go.
    I've also tried resetting the Airport to its factory settings.
    Does this mean that the Wan port is bad?
    Or is there a fix for this issue?
    Any help would be most appreciated.
    Thanks!
    Mike

    Hi Bob,
    I don't know how to pull a cable modem's internal battery.
    I can "hot swap" my airport express in and everything works fine.
    But my airport sprang back to life last night!
    (I got up during the night and set it up again on a whim.)
    Everything was working great!
    (even my Mac mini which is connected to an HDTV was able to connect to the Internet wirelessly)
    But then I needed to unplug the modem and base station (to arrange the power cords) and then no Internet again.
    I powered everything down and went back to bed.
    This a.m., I reset the airport extreme (hard reset), powered everything back on and still no Internet.
    I keep getting the "Nothing is connected to the Ethernet Wan port" message when the cable connection is secure.
    Thanks for your help!
    Mike

  • Open Save File Dialog with Default Path

    Hi All,
    I want to open a "Save File Dialog " with some default path.
    Like when user run that script I want to open  a "Save As" dialog box with default path "/Volumes/<shared name>/<folder name>/.. ."
    I am using
    File.SaveDialog(prompt, filter);
    but it doesn't open to the location by default that I want to open.
    Thanks
    Harsh

    look at this thread to see if it helps
    http://forums.adobe.com/thread/1077267?tstart=0

  • Our IT Director will not allow the appropriate TCP and UDP ports to be opened on the district WAN

    I have about 30 Apple TV Units and our IT Director will not allow the appropriate TCP and UDP ports to be opened on the district WAN.  When our teachers try to log on to Apple TV to broadcast lessons, websites, etc., they are booted off the network after about 20 minutes. 
    Any ideas for how I might solve this without having to hard-wire the Apple TV Units?

    Honestly, you do not.
    Either the IT director will cave and allow the appropriate ports or it doesn't work.
    Hard wiring the ATVs will not rectify the problem. 

Maybe you are looking for

  • Canon support says this is an Apple issue, Apple Care 3+ yrs old.

    I just purchased a Canon PIXMA MG7250 all-in-one printer.  I'm connecting via WiFi.  The printer installed correctly, the Mac recognizes it and works via WiFi just fine.  But, there are separate drivers for the printer and scanner and my Mac won't re

  • Function module/BAPI for ATP Material

    Hi All, Is there any function module/BAPI for ATP(Available-to-Promise check) for Material. 1) Production order from one plant 2) Scheduling agreement from another plant. Regards, Srinivas.

  • Noise in HP p7-1534 desk top

    Noise like a motor running.  Irritating.  Begins sometimes when computer starts or comes out of sleep, more often when computer has been running for 30 minutes or up to two hours.  Occasionally will stop and then start noise again.  Fan is running wh

  • Restricting transaction VL06O by distribution channel

    Hello, Can someone please help as I am new to this? I have added transaction VL06O to a role and I need to restrict this by distribution channel.  When I have checked in SU24, there is no authorisation object associated with the transaction that will

  • Creating a Query

    Hi experts,       I have a cube with following infoobjects.      Material        Material Description      Customer      Quantity      Value      Year      I have a requirement to design a query with the above data. Which displays      the records of