Recommended Posts

Hi,

I have openvpn server and mostly I am connected to internet through vpn.I am using it with UDP protocol(rarely TCP) also I sometimes change my UDP port for security. 2-3 weeks ago and last night(184.164.153.218), total, 3 different IP's scanned my UDP ports.After the first scan I started to monitor my router's logs. But I am confused because I saw port scans that they were trying to scan my real IP's port(which is closed I think)(between 26-50x times, don't know exact scan attempt)

How they could know my real IP and UDP protocol? Is it bad thing to happen or this is what they call "internet noise" and don't need to do anything? or there can be leak with my openvpn server setup?(I closed all incoming ports via ip tables and only allowed access from my IP to server)

Link to comment
https://www.neowin.net/forum/topic/1141616-should-i-worry-about-port-scannings/
Share on other sites

"3 different IP's scanned my UDP ports."

So you saw some UDP traffic, or they scanned 1 to 65535?

Or a HUGE range? There is a lot of NOISE on the public net, there is a bunch of udp stuff - I don't even bother to log udp stuff anymore, just fills up the logs ;)

Thank you for answers. I don't have to worry about then.

I saw some UDP traffic and all 3 ips scanned from some port range to range 5210-5230 for example and they aren't even my UDP port.

I noticed that my vpn server also has ipv6 and disabled it. Also I am thinking of installing pfsense firewall to my home as I don't trust my current router's firewall if it behaves well or not.

"they aren't even my UDP port."

Not sure what that is suppose to mean? As stated its noise.

"from some port range to range 5210-5230"

Not sure what that is suppose to mean either, yes the traffic you see would have a source port, this might change or it might be different every time depending on how the traffic is being generated.

As to your routers firewall - so you think your router is letting in traffic you have not forwarded? Behaves well as far as what?

I personally use pfsense, and yes its a great choice for your gateway/firewall solution in home or even large enterprise. But unless your trying to do something your current router does not allow you to do, other than learning there is prob little reason to change.

I am sorry, I wasn't clear enough.

"they aren't even my UDP port."

I tried to say that for example, 10.11.12.13:5410 scanned my UDP ports from myip:5210 to myip:5230 ports(5211,5212,5213,5214.......5228,5229,5230) And my UDP port was 2271.

My router brand is zyxel. Today I called their support to ask if a configuration from router is needed or not, to block these scannings, and they said that my router's firewall blocks all unauthorised connections by default and no need to change anything. But for extra security I'll setup pfsense firewall after some research.

Well if they had hit a port that you were forwarding, then most likely it wouldn't even be logged. Your router is just logging noise, ie stuff it blocked. Yes pfsense does the same thing. Unless you turn it off, all blocks will be logged.

I created a specific rule at the bottom of my list to block UDP before it gets to the default rule, just so it is not logged.. It fills up the logs all the noise.. I would be more curious to what tcp ports they are trying to hit vs UDP noise, which is most likely p2p traffic stuff.

So I am curious on your pfsense setup, did you put it behind your current router? If so your double natting? Or did you remove your other router, or put it into bridge mode so pfsense gets a public on its wan?

Hi

I haven't setup pfsense firewall yet. I am currently searching information about pfsense installation and configuration. I am thinking of buying a mini ITX pc that has two ethernet ports.(found one with reasonable price on internet)

If everything goes alright my configuration will be like this:

My current router >> pfsense firewall >> switch >> wireless router or directly to computer or both

So your current router is actually a gateway? it has a modem in it? Your going to put it in bridge mode?

If not what is the point of that in the path?

And when you say wireless router, you mean wireless router used as Acesspoint?

If I understand it correct, zyxel's mode is currently Routing and also has bridge mode.(I am adsl user and only with Routing mode I can login to my isp)

"And when you say wireless router, you mean wireless router used as Acesspoint?"

Actually I didn't think about acesspoint.

I don't know if wireless router work as acesspoint or not, so there is no need to take the risk and confusing setup process. Acesspoint will be better for me, right? (ZYXEL WAP3205, LINKSYS WAP610N or something like like these devices?)

This topic is now closed to further replies.
  • Posts

    • Honestly that feels even more useless than it did when Win11 was first released. In 2021, the uproar was somewhat justified, but only when comparing how good we've had it since Windows 7. Prior to that, a new Windows release would often require new, or very recent hardware. Windows XP wouldn't run (in any usable way) on hardware released when it's predecessor Win98 was released (let's ignore ME). It was time to shift the goal post, and the way Microsoft did that was actually ok. People have still had another FIVE YEARS of free software support with Windows 10, and those of us who want to have used these tools to bypass the limitations, all while understanding the impacts that may have. Most laptops don't last 5 years (sadly), so now the youngest unsupported hardware is 9 years old, and apparently has another year of support with Windows 10. That's good. Meanwhile, understanding the impacts and limitations, I have my 2013 laptop running Win11 perfectly fine. The thing that's failing on it is the hardware, the 2.5" SATA cable/chip is failing and corrupting the SSDs I put in. Thankfully it has a functional M.2 sata drive that works fine!
    • iPhone 18 Pro drop-test video and photos leak on the dark web following a data breach by Hamid Ganji iPhone 17 Pro - Image via Apple Apple is seemingly facing one of the biggest data breaches in its history, and just a few months before the official debut of the iPhone 18 Pro series, photos, a drop-test video, a supplier list, and key phone components have reportedly been leaked by hackers. Last week, we reported that Tata Electronics, an Apple supplier and iPhone producer in India, was hit by a data breach. As a result, it was reported that more than 200,000 trade secrets and confidential documents belonging to Apple and Tesla were stolen by the ransomware group World Leaks. According to Reuters, the group has now leaked supplier lists, component details, and photos of the upcoming iPhone 18 Pro models on the dark web. One of the materials leaked by the hackers is a drop-test video of the iPhone 18 Pro, which is due to launch this September. The phone is shown in a gray color and has the same familiar design we saw on last year's iPhone 17 Pro series. The device also appears to be quite durable, though it seems to be thicker than last year's model. One possible explanation is that Apple may be using a larger battery in the iPhone 18 Pro series. Moreover, Reuters says it has seen at least six documents mapping many components in the iPhone 18 Pro models to their respective suppliers, including details on chips on the main circuit board and on battery and camera components. The documents reportedly detail hundreds of parts that will be used in the iPhone 18 Pro models. A person familiar with the matter told the outlet that Apple classifies this data as sensitive and “is concerned about the documents being shared on the dark web as they relate to unreleased models.” Apple is reportedly investigating the issue but has yet to issue an official statement.
    • You do you, I've just said that it first appeared in "home" version before it will be available in "work" one. I use Edge only because it still supports MV2 uBO extension even on Android - I'll switch when they stop.
    • I imagine that was a review or something? My reviews mostly contain a lot of images and galleries, but these are all webp too, but yeah it all adds up on the page load. Would help if you were more helpful with your critique instead of bitching and moaning like a Karen 😂 Because then we might be able to fix it for you.
    • If Valve refused to let them make the case, I wonder if they've already partnered with someone else to do it? The fact that they didn't seek permission/licence before diving straight in is incredible though
  • Recent Achievements

    • First Post
      rosiecharles earned a badge
      First Post
    • Reacting Well
      Juan Dela earned a badge
      Reacting Well
    • Week One Done
      Collagen Project earned a badge
      Week One Done
    • Reacting Well
      Wakeen1966 earned a badge
      Reacting Well
    • Rookie
      Almohandis went up a rank
      Rookie
  • Popular Contributors

    1. 1
      +primortal
      516
    2. 2
      +Edouard
      273
    3. 3
      PsYcHoKiLLa
      142
    4. 4
      Steven P.
      100
    5. 5
      macoman
      53
  • Tell a friend

    Love Neowin? Tell a friend!