Community discussions

MikroTik App
 
BigCol
newbie
Topic Author
Posts: 35
Joined: Sat Feb 11, 2023 5:12 pm

Can the firewall drop packets silently?

Fri May 31, 2024 10:53 am

I'm using a CRS326 at home. I notice when i run an external scan of my IP address that although i have no ports open, the firewall is not only dropping packets, but is replying with 'port closed'.

Is this normal behaviour?

Is there a way for the firewall to drop packets silently? (this is what I'm used to with my old Draytek)

Thanks
 
User avatar
anav
Forum Guru
Forum Guru
Posts: 22393
Joined: Sun Feb 18, 2018 11:28 pm
Location: Nova Scotia, Canada
Contact:

Re: Can the firewall drop packets silently?

Fri May 31, 2024 3:40 pm

Using a switch as a router? Must have a tiny throughput ISP. No port should be normally seen except ICMP....
 
BigCol
newbie
Topic Author
Posts: 35
Joined: Sat Feb 11, 2023 5:12 pm

Re: Can the firewall drop packets silently?

Fri May 31, 2024 3:58 pm

its a short term solution...
 
BigCol
newbie
Topic Author
Posts: 35
Joined: Sat Feb 11, 2023 5:12 pm

Re: Can the firewall drop packets silently?

Fri May 31, 2024 4:27 pm

closedports.png
this is what ShieldsUp shows...
You do not have the required permissions to view the files attached to this post.
 
User avatar
anav
Forum Guru
Forum Guru
Posts: 22393
Joined: Sun Feb 18, 2018 11:28 pm
Location: Nova Scotia, Canada
Contact:

Re: Can the firewall drop packets silently?

Fri May 31, 2024 5:04 pm

Shields up is a very nice but not required,, I believed you the first time,
what is needed is to see why your config is letting that happen :-)

/export file=anynameyouwish (minus switch impersonating a router serial number, any public wanip information, keys etc.)
 
holvoetn
Forum Guru
Forum Guru
Posts: 6990
Joined: Tue Apr 13, 2021 2:14 am
Location: Belgium

Re: Can the firewall drop packets silently?

Fri May 31, 2024 5:06 pm

/export file=becausanavsaidso (minus switch impersonating a router serial number, any public wanip information, keys etc.)
Corrected that for you ... :lol:
 
User avatar
mkx
Forum Guru
Forum Guru
Posts: 13292
Joined: Thu Mar 03, 2016 10:23 pm

Re: Can the firewall drop packets silently?

Fri May 31, 2024 5:09 pm

My experience is that FW with drop rule does successfully hide port (it's "stealth"). If, however, port is NATed (for a particular source address), then it's up to service on the backend to handle "unwanted connection requests" ... and mostly they respond in a way interpreted as "port closed".

But yes, it really depends on how FW is set up.
 
jaclaz
Forum Guru
Forum Guru
Posts: 2298
Joined: Tue Oct 03, 2023 4:21 pm

Re: Can the firewall drop packets silently?

Fri May 31, 2024 6:33 pm

/export file=becausanavsaidso
Nice filename :lol:
possible alternative:
/export anavipsedixit

the Latin version is IMHO the best one, as it is short(er), elegant and better conveys the authority of the subject on the matter.
 
User avatar
anav
Forum Guru
Forum Guru
Posts: 22393
Joined: Sun Feb 18, 2018 11:28 pm
Location: Nova Scotia, Canada
Contact:

Re: Can the firewall drop packets silently?

Fri May 31, 2024 11:43 pm

If i were to latinize it ......................

/export file=vici-de-bici