Welcome to the Comodo Forum
Welcome,
Guest
. Please
login
or
register
.
May 17, 2008, 10:56:12 AM
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
155313
Posts
19193
Topics
47341
Members
Latest Member:
dhenz_y
more news...
Search:
Advanced search
|
Tag Cloud
Welcome to the Comodo Forum
Learn about Computer Security and Interact with Security Experts
Computer Firewalls
Cannot stealth ports with CFP3 or router.
« previous
next »
Pages:
[
1
]
2
Author
Topic: Cannot stealth ports with CFP3 or router. (Read 2239 times)
Comofo
Comodo's Hero
Offline
Posts: 248
Cannot stealth ports with CFP3 or router.
«
on:
March 25, 2008, 06:04:16 PM »
Passed all leak testing but Shields Up says it can see my ports even though I've stealthed them.
GRC Port Authority Report created on UTC: 2008-03-25 at 22:52:00
Results from scan of ports: 0, 21-23, 25, 79, 80, 110, 113,
119, 135, 139, 143, 389, 443, 445,
1002, 1024-1030, 1720, 5000
0 Ports Open
23 Ports Closed
3 Ports Stealth
---------------------
26 Ports Tested
NO PORTS were found to be OPEN.
Ports found to be STEALTH were: 21, 23, 80
Other than what is listed above, all ports are CLOSED.
TruStealth: FAILED - NOT all tested ports were STEALTH,
- NO unsolicited packets were received,
- NO Ping reply (ICMP Echo) was received.
In my Zyxel 660r-elnk settings I've tightened it up as best I could...
Is there something that I'm missing here?
Thanks
Logged
Don't let those stars fool you - 90% of those posts were questions.
XP Pro 32bit Sp2 - 2.8ghz Intel Prescot - 2gb ddr2 sdram - CFP3 [D+] - Avira Premium - CMF - SAS - F-Secure - wrt54g [dd-wrt] - notepad
sded
Global Moderator
Comodo's Hero
Online
Posts: 1654
Re: Cannot stealth ports with CFP3 or router.
«
Reply #1 on:
March 25, 2008, 06:29:22 PM »
Your "router" does not seem to have a stealth function. A NAT (Network Address Translation) router blocks all traffic that is not a response to something you sent out, and usually has a firewall that does not respond to port probes. I also had a cheap-ass Elnk crippled firmware router (PPPOE modem) several years ago, and it did not do NAT at all. And my software firewall was inundated with "internet noise". The stealth ports show up in the report because: your firmware can block telnet (port 23), ftp (port 21) and web/http (80) from responding. Ping (ICMP) doesn't use ports; SNMP is not blocked from WAN to LAN, so shows up only as closed-apparently the SNMP ports do respond. A "stealthed" port does not repond to inputs from the internet. If your router has a port that is only closed, it responds with a "request denied". If that is the case, there is obviously nothing CFP3 can do to stealth it afterward. Assuming your "elnk router" can be set up in bridge mode, so it is only a modem passing WAN data to your computer, there are a couple of options. One solution is to buy a stealthable NAT router and use your current "router" as a DSL bridge. Linksys wrt54g or gl wireless router is probably still the most popular, can be had for $40 or so, but there are lots of other good stealthy NAT routers. Another solution is to directly connect to your LAN port and set up the PPPOE connection on your computer, and let CFP3 do the stealthing.
«
Last Edit: March 26, 2008, 07:19:20 AM by sded
»
Logged
CFP 3.0.22/349, Vista Ultimate 32x + SP1, Avast! 4.8
Comofo
Comodo's Hero
Offline
Posts: 248
Re: Cannot stealth ports with CFP3 or router.
«
Reply #2 on:
March 25, 2008, 11:38:26 PM »
Thanks S,
I appreciate the information.
I'm going to investigate this further and see what I can work up. It
appears
that there's a NAT function, but I need to study up on this a bit (or a lot) and am pleading ignorance...I have to do my homework in this department before proceeding.
The good news is that I
have
a few routers laying around [SMC Barricade and a Lynksys or two] ...wondering if I can replace the elnk altogether.
I'll come back when I'm smarter.
Ps. And yes, in the title I meant modem - not router
.
«
Last Edit: March 26, 2008, 12:10:34 AM by Comofo
»
Logged
Don't let those stars fool you - 90% of those posts were questions.
XP Pro 32bit Sp2 - 2.8ghz Intel Prescot - 2gb ddr2 sdram - CFP3 [D+] - Avira Premium - CMF - SAS - F-Secure - wrt54g [dd-wrt] - notepad
sded
Global Moderator
Comodo's Hero
Online
Posts: 1654
Re: Cannot stealth ports with CFP3 or router.
«
Reply #3 on:
March 26, 2008, 04:26:35 AM »
Sorry for adding to the confusion; I made some corrections to the previous message.
You do have the NAT function, of course, but not apparently the firewall/stealth capability that usually goes with it in a NAT router. Elnk did actually send me a NATless PPPOE modem I remember less than fondly. Without NAT, some of your ports would show as open. You probably can't replace it entirely, because you need the modem part, but putting it into bridge mode should let you use both the NAT and firewall/stealth capabilities of the Linkysy or SMC router and allow stealthing of your ports. It should also do the PPPOE. Unless you can find a setting on your current router that turns off WAN responses.
«
Last Edit: March 26, 2008, 07:22:07 AM by sded
»
Logged
CFP 3.0.22/349, Vista Ultimate 32x + SP1, Avast! 4.8
Comofo
Comodo's Hero
Offline
Posts: 248
Re: Cannot stealth ports with CFP3 or router.
«
Reply #4 on:
March 26, 2008, 05:08:45 AM »
Thanks again sded,
While I was away I did some homework and; Yes, you're right on the $$$ (as usual
)
Looks like the Barricade is the bad boy of the two and there's even a "wizard" in my web configurator to help me along the way. Other like-minded forums are all indicating that this is a proverbial cakewalk...so I'll no doubt be stymied. Sometimes I feel like an ape with an abacus.
Obliged
Logged
Don't let those stars fool you - 90% of those posts were questions.
XP Pro 32bit Sp2 - 2.8ghz Intel Prescot - 2gb ddr2 sdram - CFP3 [D+] - Avira Premium - CMF - SAS - F-Secure - wrt54g [dd-wrt] - notepad
Vettetech
Computer Security Testing Group
Comodo's Hero
Online
Posts: 2133
Re: Cannot stealth ports with CFP3 or router.
«
Reply #5 on:
March 27, 2008, 12:53:11 AM »
Thats odd. I have a 2Wire Gateway DSL Modem with a hardware firewall and I have alot more options then just yours Comofo. I dont even need a software firewall to pass any on site port test all stealthed. Like sded said check your stealth settings and echo ping if there is an option.
Logged
Comofo
Comodo's Hero
Offline
Posts: 248
Re: Cannot stealth ports with CFP3 or router.
«
Reply #6 on:
March 27, 2008, 01:11:19 AM »
Thanks Vet,
I know...either I'm completely ignorant to the methods of doing this, or there are no such options available with the p660r-elnk. The only security measures I can find are what you see in my pic above - which I obviously have as tight as they can be (ping is there).
I'm currently checking with the folks over at dsl reports to confirm this, but I think I'll be employing the Barricade before too long. Here's what they've said:
The ZyXEL P660R is a Router. Its default setup mode is Router Mode and the ZyXEL P660R uses NAT/NAPT since the ZyXEL obtains a Public IP from EL and it hands our Private IPs to PCs connected to it on the LAN (multiple PCs can be added by purchasing a simple 10/100 Multi-Port Switch. As the first FAQ below states, The ZyXEL P660R once configured supports "up to" 32 PCs since it is preset to hand out that many Private IPs by default on its DHCP server settings page. It can actually be set to handle "up to" 253 PCs like any Router if you add enough ports.
...but this doesn't really help me...does it?
Logged
Don't let those stars fool you - 90% of those posts were questions.
XP Pro 32bit Sp2 - 2.8ghz Intel Prescot - 2gb ddr2 sdram - CFP3 [D+] - Avira Premium - CMF - SAS - F-Secure - wrt54g [dd-wrt] - notepad
sded
Global Moderator
Comodo's Hero
Online
Posts: 1654
Re: Cannot stealth ports with CFP3 or router.
«
Reply #7 on:
March 27, 2008, 07:44:44 AM »
Not really a help. It is a single port router, which is good since you can just use a switch for distribution-I didn't see the DHCP function in your pictures, but apparently it has one-probably on the LAN tab. Don't understand why it doesn't stealth the ports, but the technical spec for TCP/IP is to respond with a nack/ack, not remain silent-just almost no one does that anymore for internet routers because of security concerns. Check again for an obscure setting that turns off the responses-you showed us it's not there on the security tab, so maybe the WAN tab? I wonder if the non-elnk version has a "firewall tab"? Often the "free" ISP routers have something like that disabled so you can't sell them on eBay in competition with the vendor version.
Logged
CFP 3.0.22/349, Vista Ultimate 32x + SP1, Avast! 4.8
Comofo
Comodo's Hero
Offline
Posts: 248
Re: Cannot stealth ports with CFP3 or router.
«
Reply #8 on:
March 27, 2008, 08:58:25 AM »
Before I read the 20,000 word manual I thought I'd post these for the heck of it - in case you see something I don't.
I really do appreciate the extra help here guys, I'm fully aware this is almost entirely out of Comodo territory.
Obliged,
mo
«
Last Edit: March 27, 2008, 09:03:49 AM by Comofo
»
Logged
Don't let those stars fool you - 90% of those posts were questions.
XP Pro 32bit Sp2 - 2.8ghz Intel Prescot - 2gb ddr2 sdram - CFP3 [D+] - Avira Premium - CMF - SAS - F-Secure - wrt54g [dd-wrt] - notepad
sded
Global Moderator
Comodo's Hero
Online
Posts: 1654
Re: Cannot stealth ports with CFP3 or router.
«
Reply #9 on:
March 27, 2008, 09:14:37 AM »
Change NAT mode to "full feature" and see what happens under "edit details".
Logged
CFP 3.0.22/349, Vista Ultimate 32x + SP1, Avast! 4.8
Comofo
Comodo's Hero
Offline
Posts: 248
Re: Cannot stealth ports with CFP3 or router.
«
Reply #10 on:
March 27, 2008, 02:16:34 PM »
Got it. Rooks rike this...
Logged
Don't let those stars fool you - 90% of those posts were questions.
XP Pro 32bit Sp2 - 2.8ghz Intel Prescot - 2gb ddr2 sdram - CFP3 [D+] - Avira Premium - CMF - SAS - F-Secure - wrt54g [dd-wrt] - notepad
sded
Global Moderator
Comodo's Hero
Online
Posts: 1654
Re: Cannot stealth ports with CFP3 or router.
«
Reply #11 on:
March 27, 2008, 03:01:55 PM »
Does "full feature" stealth your ports? If not, turning off "SIP ALG" looks like your last chance.
Logged
CFP 3.0.22/349, Vista Ultimate 32x + SP1, Avast! 4.8
Comofo
Comodo's Hero
Offline
Posts: 248
Re: Cannot stealth ports with CFP3 or router.
«
Reply #12 on:
March 27, 2008, 10:21:54 PM »
Ya know...I don't know.
What'da think of this (reading manual.pdf presently)
«
Last Edit: March 27, 2008, 11:57:56 PM by Comofo
»
Logged
Don't let those stars fool you - 90% of those posts were questions.
XP Pro 32bit Sp2 - 2.8ghz Intel Prescot - 2gb ddr2 sdram - CFP3 [D+] - Avira Premium - CMF - SAS - F-Secure - wrt54g [dd-wrt] - notepad
Vettetech
Computer Security Testing Group
Comodo's Hero
Online
Posts: 2133
Re: Cannot stealth ports with CFP3 or router.
«
Reply #13 on:
March 28, 2008, 12:31:50 AM »
In all those tabs there isn't a thing about stealthing any where, odd. Really odd. Time to get e new modem. LOL. Here is a screen shot of my 2Wire DSL modem.
Logged
Comofo
Comodo's Hero
Offline
Posts: 248
Re: Cannot stealth ports with CFP3 or router.
«
Reply #14 on:
March 28, 2008, 01:47:32 AM »
Thanks Vet,
I know...it's starting to PMO too. The support forums keep telling me "it IS a NAT router" and I say " I know, but it doesn't seem to stealth - so should I bridge another w/ NAT stealthing capabilities?" to which they'll say "Don't you get it? It is a NAT router. What don't you understand?" and so on in that manner until there's a vain poking out of my forehead.
So it seems that I'm only able to block traffic - and hide nothing. I don't know...nobody does...if they do, they're not talking.
I don't think I can ditch the Zyxel altogether with Jerk-Link the way they are...wonder if they'd be willing to sell me a slightly better one for more than it's worth? That'd be great.
I appreciate you guys taking the time though...really.
Logged
Don't let those stars fool you - 90% of those posts were questions.
XP Pro 32bit Sp2 - 2.8ghz Intel Prescot - 2gb ddr2 sdram - CFP3 [D+] - Avira Premium - CMF - SAS - F-Secure - wrt54g [dd-wrt] - notepad
Tags:
Pages:
[
1
]
2
« previous
next »
Jump to:
Please select a destination:
-----------------------------
General Category
-----------------------------
=> General Discussion (off topic) Anything and everything...
-----------------------------
Desktop Security Products
-----------------------------
===> Help for v2
=> AntiSpam
=> Comodo Anti-Viruspyware (CAVS)
=> Backup
-----------------------------
Free Services for End Users
-----------------------------
=> Hacker Guardian
-----------------------------
Desktop Security Products
-----------------------------
=> i-Vault
=> Launch Pad
-----------------------------
Free Services for End Users
-----------------------------
=> Comodo Meet (Web Conferencing Product)
-----------------------------
Web Server Products
-----------------------------
=> Trustlogo
-----------------------------
Desktop Security Products
-----------------------------
=> Trusttoolbar
=> Verification Engine (allows you to verify what you see on the Internet)
-----------------------------
Digital Certificates
-----------------------------
=> SSL Certificate
=> Email Certificate
=> Content Verification Certificate
=> Code Signing Certificate
-----------------------------
Free Services for End Users
-----------------------------
=> Trustfax (free Trial) (online faxing)
-----------------------------
Infrastructure Products
-----------------------------
=> Trustix Enterprise Firewall
-----------------------------
Want to help Comodo?
-----------------------------
===> Help spread the word! (Please read and help)
-----------------------------
Infrastructure Products
-----------------------------
=> ZTL
-----------------------------
General Category
-----------------------------
=> Which Product do you want Comodo to develop next?
-----------------------------
Free Products
-----------------------------
=> Link to Free Comodo Products
-----------------------------
International Comodo Forums
-----------------------------
=> International Comodo Forums
===> Italiano / Italian
===> ελληνικά / Greek
===> Turkce / Turkish
-----------------------------
Desktop Security Products
-----------------------------
===> Frequently Asked Questions (FAQ) for Comodo firewall
-----------------------------
Want to help Comodo?
-----------------------------
=> Please tell us your views and Vote here!
-----------------------------
Free Services for End Users
-----------------------------
=> User Anywhere (Remote Access product)
-----------------------------
International Comodo Forums
-----------------------------
===> Espanol / Spanish
-----------------------------
General Category
-----------------------------
=> Melih's Corner - CEO Talk/Discussions/Blog
-----------------------------
International Comodo Forums
-----------------------------
===> Português/Portuguese
-----------------------------
Want to help Comodo?
-----------------------------
=> How can you help Comodo? (Please we do need you!)
-----------------------------
International Comodo Forums
-----------------------------
===> Nihongo / Japanese
-----------------------------
Desktop Security Products
-----------------------------
===> FAQ for Comodo Anti-ViruSpyware
-----------------------------
Want to help Comodo?
-----------------------------
===> Comodo website issues for submitting website problems only
-----------------------------
General Category
-----------------------------
===> Member Confessions :-)
===> Funny Photos :-)
===> Cool Stuff
-----------------------------
Desktop Security Products
-----------------------------
=> Comodo Firewall
===> Feedback/Comments/Announcements/News
===> Leak Testing/Attacks/Vulnerability Research
-----------------------------
** New to the Comodo Forum? Start Here! **
-----------------------------
=> New Member Information
-----------------------------
Desktop Security Products
-----------------------------
===> Virus/Malware Removal Assistance
===> Comodo Firewall Translations
-----------------------------
International Comodo Forums
-----------------------------
===> Svenska / Swedish
-----------------------------
Want to help Comodo?
-----------------------------
=> Help Spread the Word - Official Comodo banners and logos
-----------------------------
Learn about Computer Security and Interact with Security Experts
-----------------------------
=> Computer Firewalls
=> Anti Virus/Malware Products/Other Security products
=> Anti Phishing solutions
=> HIPS (Host Intrusion Prevention Systems)
=> Digital Certificates, Encryption and Digital Signing
-----------------------------
International Comodo Forums
-----------------------------
===> Francais / French
===> По-русски / Russian
===> 汉语语言, 漢語語言 / Chinese Simplified, Traditional
===> Nederlands / Dutch
===> Magyar / Hungarian
-----------------------------
Desktop Security Products
-----------------------------
=> Comodo Secure Email (CSE) Product
===> CSE Beta Corner
-----------------------------
International Comodo Forums
-----------------------------
===> Deutsch / German
===> Polski / Polish
===> Norsk / Norwegian
===> Українська / Ukrainian
-----------------------------
Desktop Security Products
-----------------------------
=> Comodo BOClean Anti-Malware
===> Comodo BOClean Anti-Malware FAQ
-----------------------------
Learn about Computer Security and Interact with Security Experts
-----------------------------
=> General Security Questions and Comments (not product related)
-----------------------------
Desktop Security Products
-----------------------------
===> Help for Comodo AntiVirus
-----------------------------
International Comodo Forums
-----------------------------
===> tiếng Việt / Vietnamese
-----------------------------
Desktop Security Products
-----------------------------
===> Announcements
===> Feedback/Comments/Announcements/News about CAVS
=> Comodo Memory Firewall(Buffer Overflow Protection)
===> Help
===> Frequently Asked Questions (Comodo Memory Firewall)
===> FAQ for Comodo Backup
=> Comodo TrustConnect - Securing the Wireless world!
===> Help
===> Help for v3
===> Bug Reports
===> Feedback/Comments/Announcements/News
-----------------------------
Free Services for End Users
-----------------------------
=> UserTrust - First Independent Website Rating - Empowering our users!
-----------------------------
Web Server Products
-----------------------------
=> Two Factor Authentication for Web Applications
-----------------------------
Other
-----------------------------
=> Forum Policy Violation Board
-----------------------------
Desktop Security Products
-----------------------------
=> Comodo Vulnerability Analyzer
-----------------------------
Learn about Computer Security and Interact with Security Experts
-----------------------------
=> Free Virus/Spyware/Trojan/Malware Removal by Comodo Experts
Page created in 0.217 seconds with 18 queries.
Powered by SMF 1.1.5
|
SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by
7dana.com