› UKTH forums › 🛜 Wireless Routers & Modems › 🗨 AVM & Wireless › Fritz!Box 3490 Port 113 Closed (Not in Stealth)
- This topic has 22 replies, 4 voices, and was last updated 2 months ago by
UK Sentinel.
-
AuthorPosts
-
March 2, 2019 at 4:26 pm #2319
Ok, So I plugged back in my Fritz!Box 3490 yesterday and it is running the latest firmware (07.01) and have run a GRC SHIELDSUP (https://www.grc.com) test on the router to see if all ports are in Stealth mode, I was surprised to find that port 113 is CLOSED, but not in Stealth mode.
I thought I had run this test in the past, maybe with an older firmware, and the GRC Shields up test reported all ports where in Stealth mode?
Port 113 is associated with the IDENT Service and my Fritz!Box is running dual IPv4 and IPv6 setup, so maybe something I have missed , cannot seem to find a way to fully stealth this specific port, or find the associated service using port 113?
For those reading this thinking, maybe port 113 should be CLOSED and not STEALTHED, I have heard the discussions, I raised this thread as the Friz!box has a very specific setting called ‘Firewall in Stealth Mode’, which can be toggled On or Off, hence my original question .
In a completely sane world, madness is the only freedom (J.G.Ballard).
You need to login in order to vote
December 19, 2021 at 8:31 pm #16787December 19, 2021 at 8:45 pm #16788yep on a fitz!box 7590 how do I stealth this port
Well officially via AVM ‘No’ – but have a read of this thread as some have tried this option with success, make sure you test all your ports afterwards just to make sure ?
Stealthing port 113 on NAT routers
https://www.grc.com/port_113.htm
———
In Brief:
In theory to configure a NAT routers to full stealth. The trick is to use the router’s own
“port forwarding” configuration options to forward just port 113 into Very high ip address.i.e.
Set the router to forward port 113 packets to a completely non-existent IP address, one way up at the end of your router’s internal address range. The router will then NOT return a port closed status. It will simply forward the port 113 packet “nowhere” . . . and your network will be returned to full stealth (in theory)
Never tried this but does sound feasible.
In a completely sane world, madness is the only freedom (J.G.Ballard).
You need to login in order to vote
February 21, 2022 at 11:59 am #17899tried the forward port way up high to nothing did not work on my fritz!box 7590
You need to login in order to vote
February 21, 2022 at 1:41 pm #17900tried the forward port way up high to nothing did not work on my fritz!box 7590
Can you show us the configuration you used and how are you testing if Port 113 is OPEN/Stealth etc ?
In a completely sane world, madness is the only freedom (J.G.Ballard).
You need to login in order to vote
February 21, 2022 at 6:48 pm #17903I used Inernet->Permit Access->Add Device For Sharing...
then I chose- Device:
Enter the IP address manually
- IPv4 address:
192.168.188.254
- clicked
New sharing...
then I added
- Application:
Other application
- name:
Null
- Protocol:
TCP
- Port to Device:
113
- through… :
113
- Port requested: externally:
113
then
OK
Apply
- and
Apply
again to get the green bubble.then I tested with
shields up
on https://www.grc.com/x/ne.dll?rh1dkyd2 using both
Common ports
and probing just133
usingUser Specified custom port Probe
tried doing UDP as well still the same result Closed but not Stealth
most disappointing
You need to login in order to vote
February 21, 2022 at 7:59 pm #17905February 21, 2022 at 8:10 pm #17906Can 192.168.188.254 be replaced with say 254.254.254.230 ?
In a completely sane world, madness is the only freedom (J.G.Ballard).
You need to login in order to vote
February 21, 2022 at 8:18 pm #17908February 21, 2022 at 8:21 pm #17909An error occurred.
Error description: The IP address is not located in a permissible FRITZ!Box network.
You need to login in order to vote
February 21, 2022 at 8:23 pm #17910Oh well, worth a try, so seems my suggestion does not work
Edit: can both TCP and UDP be forwarded as you have originally (2 rules) ?
In a completely sane world, madness is the only freedom (J.G.Ballard).
You need to login in order to vote
February 21, 2022 at 8:32 pm #17912You cant forward to an address outside your home subnet (must result in a failure)!
Of course I tried setting the rule for both UDP and TCP, each in a seperate rule and for IPv4 and IPv6.
You need to login in order to vote
February 21, 2022 at 8:45 pm #17913Oh well, seems port 113 for Fritz!box cannot be put into Stealth, only Closed or Open ?
In a completely sane world, madness is the only freedom (J.G.Ballard).
You need to login in order to vote
February 21, 2022 at 9:01 pm #17914Wish they would tell us why it cannot be stealthed and why I cannot turn of ICMP ping
You need to login in order to vote
February 21, 2022 at 9:30 pm #17915 - Device:
-
AuthorPosts
- You must be logged in to reply to this topic.