WRT54GS firewall

Hi
i have the wrt54gs but how can i be sure that the firewall within it is working properly. i still get some alerts on my mcafee firewall centre but shouldnt the router stop most of these attempts to my ports?

Occasionally, some things do make it through the router, and that is part of the reason that I also run a software firewall.
The router's firewall primarily protects the router.  The router's NAT (network address translation) provides most of the protection for your computers.  The NAT is always on.  The NAT provides protection that is somewhat similar to the protection provided by a software firewall.
To check out your system, first verify that your router firewall is on.  Enter the router and go to the "Security - firewall" tab.  Make sure the firewall is enabled.  Also, most users will also want to check the boxes labeled "Block WAN requests" and "Filter Ident (port 113)".
On the "Administration" tab, most users will want UPnP set to "disabled".  If UPnP is enabled, programs on your computer can open the router's ports for extended periods of time.  Unless you need UPnP, it should be disabled.
If you had to change any router settings, power cycle your entire system.
Next go to a security web site and test your ports to see if they are "stealth".  You can do this at:
Gibson Research (grc.com) - use the "Shields UP" program, and test all the commonly used ports 0 thru 1056.
Symantec.com - do a "Security Scan"
If you find any "open" ports, you probably have some software on your computer that is opening the ports.  (Having UPnP disabled stops some, but not all of this problem.)  This could be almost any program including games, video conferencing, P2P networking, or even a virus.  It is usually hard to track down what program is opening ports.  Sometimes checking the router logs will help determine what program is doing it.  If you know how to use MSCONFIG and shut down some of your startup programs, sometimes this will help track down the offending program.  If all of your ports are "stealth", you will get less complaints from your software firewall.   
Message Edited by toomanydonuts on 03-21-200706:18 AM

Similar Messages

  • WRT54G Firewall

    It seens that my WRT54G router will not allow me to download some updates I need. Can anyone tell me how to disable the firewall or how to make an acception?

    If you have McAfee anti-virus, then I guarantee IT IS a McAfee + Vista issue. In the Firewall settings for Vista, enable Peer-to-Peer and add and enable ports TCP 5357, TCP 5358, UDP 3702, TCP 2869, UDP 1900, UDP 137, UDP 138, TCP 139, TCP 445. THEN, disable Vista Firewall and enable McAfee Firewall. Click on Internet & Network Protection and then Configure. This is where the McAfee Firewall protection is enabled. Click on the Advanced tab. Click on Grant Full Access and apply. Click OK, close out and reboot. Your system will utilize the McAfee Firewall and not the Microsoft one, and as long as you have WAP encryption and a private network, your Linksys router will allow printer and file sharing and be protected.

  • WRT54GS - Firewall - adding program to router's firewall

    Need help.  I have ATX 2007 tax software and I'm trying to do an e-filing.  I contacted software vendor and was walked through adding the software in exceptions using Windows Firewall.  I also disabled the windows firewall but still could not do a filing.  I kept getting error message of no internet connection.  Strange thing about this, I have ATX 2006 software and able to do e-filings and connect to internet.  The techies at ATX said the problem was the router.  They tried entering my computer remotely but could not get through because again they said router's firewall is blocking.  How can I add my software through the router's built-in firewall?  In the meantime, I have to revert back to dial-up (ugh!) on my old laptop just to do e-filings for my clients.  Any suggestions?

    The router only works with a broadband cable/dsl connection and not dial-up. Can you get online with the router?
    The box said windows xp or better... So I installed Linux!

  • [HELP!!]After Firmware upgrading, **bleep**! So how can I turn off the WRT54G Firewall? Thanks!!

    One program was using fine when using previous firmware and now facing firewall problem after upgrading.
    Can anybody help me to turn off the firewall?
    THanks a lot!

    Hi… Well I think both the firmware’s does have a firewall and disabling this altogether may not be the best solution for the problems you are facing. Please give the exact details of the issue. Also just to mention, after upgrading the firmware, reset the router and reconfigure it. If you need to open the ports on that firewall, you can go to gaming and application tab either forward or trigger the ports as per you requirements.

  • I want to block incoming ports WRT54G!

    Hi!, I want to block some ports for aplications from incoming data , im enabling the router "Wrt54g" firewall and disable Upnp. Ok im going to grc.com "Shieldsup test" are stealch! All apps ( nod32, firefox, messenger msn) can open ports! Why the applications turn on the ports? , Do they appear "stealch" but not closed? From outgoing ports im using comodo firewall on vista. Thanks! and sorry my english!

    on the router's web ui , click on the "access restrictions" tab and block the ports you want ...

  • How do you turn off SPI Firewall for WRT54G?

    While browsing ebay, I've noticed loading speeds are drastically different with and without the router.  Its faster without the router(normal, est. 5 sec. or less to load an ebay auction page) and slower with the router(est. 25+ seconds to load an ebay auction page).
    Linksys support page does not help. It bluntly states how some software firewalls do not work with the router and to disable and remove the software firewall if any trouble arises.
    I've seen the data sheets for the WRT54G.  Under the data sheet's Firewall tab, there is an option to turn off SPI but mine doesnt have that option.  Im guessing that its a firmware update but I would rather not update if i dont have to.
    If anyone has any ideas on how to do this, it would be a great help.

    What version of the WRT54G are you using ? I'd suggest upgrading the firmware or try reducing the MTU on your router.

  • WRT54G connecting to Netgear fvs338 Firewall

    Has anyone connected a WRT54G behind a Netgear Firewall.  I can't seem to get the Lynksys to connect to the Netgear Firewall.  I don't need the router but I do need the wireless.  I have to use the Netgear FVS for work.  Any help appreciated!!!

    Okay… configure the linksys router according IP range of firewall, if firewall is running on e.g. 192.168.1.1 and change LAN IP of router to 192.168.1.2 and disable the DHCP server and save the settings, make LAN to LAN connection between firewall and router and power cycle the n/w check whether it works or not…

  • WRT54G - Is there anyway to add a separate VPN/Firewall device to complement this product

    I have a WRT54G v.2 device and I hate to throw it out.  My dilemma is that I'm in need of a VPN/Firewall device as well.  So I would like to know if there is a device that I can purchase from Linksys that will provide the VPN/Firewall features as a complement to my existing WRT54G?  I'd appreciate any info someone might be able to provide.
    Regards.

    Hi,
    you have options between the RV series of VPN routers and the BEFSX41 and the BEFVP41.however you will have to change your network a bit.Your main router will have to be either of the VPN routers.The DHCP of the wrt will have to be disabled and you will also need to change the ip of the wrt from 192.168.1.1 to 1962.168.1.2
    The connection will be.modem to internet port of the VPN router and then from port 1 of the VPN router to port 1 on the wrt.Do not use the internet ports of the wrt.

  • WRT54GS - MAC Address Filter & Firewall SPI

    Hi,
    I just purchased a WRT54GS V 6 wireless router.  I updated the firmware to the latest (May 30) and the set up seems to be OK.  Using the security recommendations in the manual as a guide, I implemented them - the turn off SSID, and the others. 
    IF I try to filter the MAC addresses (accept only those on the list) for my wife's Sony VAIO VGN - S260 laptop, it can see the network but will not connect. When I turn off the MAC filtering, it is fine.  I used the WPA2 personal encryption, and input the passphrase into both router and computer. 
    My other issue is the firewall Statefull Packet Inspection (SPI).  On the Security set up screen, firewall tab - I have the four radio button settings that I am supposed to (Block WAN request, filter Multicast, Filter NAT, & Filter IDENT), however, I do NOT have the option to turn on the firewall (SPI) above the 4 radio buttons - that setting is totally missing from the set up screen.  Reference Page 28 of the manual.
    I would appreciate any help or suggestions, as I could not find any ideas searching the forum.  Thanks for your help
    Message Edited by donh127 on 08-07-2006 07:00 PM

    Hi. Is your Mac mini loaded with the OSX server edition or OSX consumer edition? I am not 100% sure but I think you need a server edition to do that.

  • WRT54g with VPN Firewall

    Would like to configure the VPN firewall with my existing system.  I have Verizon DSL which involves the DSL modem and the Firewall.  I have the IP addresses of each.  How would I determine an appropriate IP address for the firewall.  Should the device be physically connected between the DSL modem and the router?  Advice sought

    The router has it's own firewall I would turn the firewall in the modem off or at very least put your computer in the DMZ of the modem so that it's firewall doesn't affect you. By default the router is already set to allow VPN connections using IPsec PPTP and L2TP Protocols. @ this point your router will still act as your firewall and you will be able to access VPN.
    Vista Ultimate 32 Bit
    AMD 64 X2 6400+ Black Edition
    4BG RAM
    1.18 Terabytes Of Hard Drive Space
    Acer 22inch Widescreen LCD
    Nvidia 8600 GT PCI E 512 DDR3
    WRT54G Router
    Netgear Gigabit Switch
    Motorola 2210 Modem

  • WRT54G on 2900 switch, seperate VLAN, out same firewall

    Our current network (subnet 10.24.167.0) uses a Sonic Wall firewall (10.24.167.254) as the gateway and PAT device to our router.
    The owner wants guests to be able to use our internet wirelessly but have no chance of getting on our network.
    I want to put the wireless Linksys router (WRT54G) on a seperate VLAN and give it (and the DHCP pool) a different subnet (192.168.1.0). Is that wireless "router" going to be good enough to get the data from the guest subnet out our firewall (which is on the company subnet) and out the router?
    Can you please explain the best way to get this to work?
    I was also considering a bridge off the router with 1 port going to the firewall and our company subnet, and another port going to the WRT54G, but I think there is a better way.

    Hi,
    Just addition to the earlier post, see if your firewaal supports trunking and use the trunking feature instead of a separate interface, whihc can be used later for some more specific purpose.
    Rest is the same as above.
    regards,
    -amit singh

  • WRT54G, Question about firewall

    I am using a WRT54G router & since I have had it installed I am not able to host any games using my PC (mostly Commando 2 & 3), I can join a already open game but am not able to start a game I host.
    I was told it is due to the routers firewall.
    Would this be true & can I turn it on & off etc?
    Thanks

    This is not due to the routers firewall. The routers firewall protects the router. It doesn't do much more. Turning off the router's firewall basically removes the protection from the router. Therefore, never turn off the router's firewall!
    The problem is that you are running a private network behind the router in gateway mode. In gateway mode your router does network address translation (NAT) which means it has a single internet (aka public) IP address while in your LAN you have a whole network of 255 addresses usually 192.168.1.1-255.
    Due to NAT computers in the LAN are not accessible from the internet. Obviously your router cannot know what to do with an incoming connection on some port (let's say 10000) on your internet IP address as there are 254 addresses in your LAN which are potential recipients for this connection.
    The router only lets traffic in which was initiated before in the LAN. You have no problems joining games because the communication started from the computer in your LAN. Unfortunately, many games are not designed properly to handle cases when hosting a game behind a NAT router.
    Therefore you have to tell the router to accept certain incoming traffic and forward it to the computer in your LAN which hosts the game. Configure your router at http://192.168.1.1/ . Look for the "Port Forwarding" subtab which usually is somewhere on the tab "Applications & Gaming". You must find out which incoming port numbers your game requires for hosting. You must also find out the IP address of your computer in your LAN which is hosting the game.
    Then you specify the port forwarding in the router, entering the port number range (e.g. 10000 and 10000 if you only need the single port 10000) the protocol (usually you'll leave it on "Both") and the IP address of the computer. Check enable. If you need several ports fill in more forwardings. Save the settings.
    Now the router will forwarding incoming traffic on port 10000 to the IP address in your LAN, i.e. your computer.
    You may consider assigning a static IP address in your computer. Usually computers connected to the LAN run DHCP and get a dynamic IP address. This IP address may change over time/after reboots. You would then have to adjust the port forwardings in the router. To avoid this, you could assign a static IP address in 192.168.1.2-99 and 150-254 on the computer. If the computer is configured with a static IP address it will always use this address.

  • Setting Up a WRT54GS Inside a Firewalled Network

    Hi hi!
    Aaargh!! I hate these little things sometimes.
    I'm the IT Director for a small refining company. I'm running a Windows 2000 network workgroup. We're behind a Watchguard Firebox, so I use static IPs to access the outside world.
    A standard hard wired PC set up would look like this:
    IP: 192.168.1.xxx (xxx=100-199)
    Subet: 255.255.255.0
    Gateway: 192.168.1.2
    DNS: 216.99.225.30
    I'm now hooking up a WRT54GS to one of our inside ports so that a new notebook PC can be use a wireless connection.
    Maybe I have it figured wrong, but it seems I should be able to set a Static IP for the 54GS, using the settings listed above, then allow for DHCP so the notebook - also using DHCP can access the router, which in turn accesses the company LAN and the Internet. If not that, I can also go Static IP between the router and notebook. (I only use about 25 IP addresses, so I have plenty of room.)
    When I try to set the Static IP for the router under the Internet Connection Type on the Basic Setup screen, I get the vague error:
    "The WAN IP address is same with the LAN IP address! Please check them again!"
    This tells me almost nothing. (Yes, the wording is weird.) It's referring to the Internet IP Address field on the Basic Setup screen, but any IP address using 192.168.1.xxx returns the same dialogue window.
    I spent a couple hours with Linksys tech in India, trying to get it solved, but to no avail. About all I learned from THAT was the router really hates being readdressed to 192.168.2.1 because once it has been, the setup screen can NOT be accessed again.
    Please advise. I have five sons at home, so I don't really NEED this added aggravation.
    Thanks!
    Rachel Prellwitz
    IT Director
    Garfield Refining Company
    Philadelphia, PA

    I have Dg834v2 as well which is a pain the neck with my macs, passwords and encryption methods are not remembered for more than a day or two by either of my os x laptops. Constantly interfered with by another Netgear router on the same street despite almost daily channel changes. ugh...
    The only way I can get any stability at present is to disable all security in the Netgear and only allow the specific mac addresses of each laptop to connect. No idea if this secure and crazy though it is my Powerbook behaves far better as the only mac on the school windows wireless network than at home in a mac only environment !
    Good luck with it!
    Andy

  • Wrt54g and hughesnet hn7000s. firewall fails sheildsup.(help the newbie)

    Hello im still new to the networking stuff so here it is, no matter which computer i use(LAPTOP,DESKTOP,IMAC) it fails the sheildup test on grc.com everytime. for some reason when i go to dialup it passes the test.i set up the router again another failure. i have also looked into the hn70000s modem called tech support, no help there.
    is my problem the router or the modem, i did find settings page for modem that had a modem disabled box but no way to enable.
    thats about alli know, please help!

    O.K. First, let's find out what you are doing.
    When you run the test, how exactly is your setup:
    - if your router is connected to the modem, any port scan service in the internet will always scan the router. It does not matter from which computer inside your LAN you start the scan. You have one internet IP address which is assigned to the internet interface of the router. Therefore, the test must also ways report the identical results regardless from the computer behind the router which starts the scan. Due to the NAT router the computer behind the router is not directly accessible not is it possible to scan the computer behind the router unless you configure a DMZ or port forwarding.
    - If the computer is directly connected to the modem and connects to the internet a port scan service in the internet will actually test the open ports on the computer itself.
    Thus, if you scan through the router (without DMZ or port forwarding) the firewall on the computer itself is irrelevant.
    Second, you don't write what test you do exactly. There is no direct button on grc.com to "test all ports". You can test all service ports which is ports 0-1055.
    Third, if the port scan reports most of the ports as "open" this is very unlikely to be true. All ports open would mean that there is some service listening on those ports. Even the fattest server with a lots of services will never listen to all those ports.
    You should check what device actually is in the front line, i.e. really connected to the internet directly on the IP level. The internet port scan like grc reports your current IP address. This is usually the IP address assigned by your ISP. Please check the status on your WRT to see what IP address it is actually using. Open http://192.168.1.1/ and go to the Status tab. There you can see the IP address of the router on the internet interface. If this is not the IP address mentioned in the port scan your router is actually not directly connected to the internet. In that case your modem is most likely also a router device. If you see open ports in a port scan those would be on the modem/router and not on the WRT.

  • How can i disable the SPI Firewall built in my WRT54G Ver.5?

    plz help, guys!!!

    There is no way to disable this firewall. If you need to open any particular traffic out of this router then you can go port forwarding, port triggering or DMZ, depending upon your requirement. If you have any specific requirements revert back.

Maybe you are looking for