Recommended Posts

Hi,

I have openvpn server and mostly I am connected to internet through vpn.I am using it with UDP protocol(rarely TCP) also I sometimes change my UDP port for security. 2-3 weeks ago and last night(184.164.153.218), total, 3 different IP's scanned my UDP ports.After the first scan I started to monitor my router's logs. But I am confused because I saw port scans that they were trying to scan my real IP's port(which is closed I think)(between 26-50x times, don't know exact scan attempt)

How they could know my real IP and UDP protocol? Is it bad thing to happen or this is what they call "internet noise" and don't need to do anything? or there can be leak with my openvpn server setup?(I closed all incoming ports via ip tables and only allowed access from my IP to server)

Link to comment
https://www.neowin.net/forum/topic/1141616-should-i-worry-about-port-scannings/
Share on other sites

"3 different IP's scanned my UDP ports."

So you saw some UDP traffic, or they scanned 1 to 65535?

Or a HUGE range? There is a lot of NOISE on the public net, there is a bunch of udp stuff - I don't even bother to log udp stuff anymore, just fills up the logs ;)

Thank you for answers. I don't have to worry about then.

I saw some UDP traffic and all 3 ips scanned from some port range to range 5210-5230 for example and they aren't even my UDP port.

I noticed that my vpn server also has ipv6 and disabled it. Also I am thinking of installing pfsense firewall to my home as I don't trust my current router's firewall if it behaves well or not.

"they aren't even my UDP port."

Not sure what that is suppose to mean? As stated its noise.

"from some port range to range 5210-5230"

Not sure what that is suppose to mean either, yes the traffic you see would have a source port, this might change or it might be different every time depending on how the traffic is being generated.

As to your routers firewall - so you think your router is letting in traffic you have not forwarded? Behaves well as far as what?

I personally use pfsense, and yes its a great choice for your gateway/firewall solution in home or even large enterprise. But unless your trying to do something your current router does not allow you to do, other than learning there is prob little reason to change.

I am sorry, I wasn't clear enough.

"they aren't even my UDP port."

I tried to say that for example, 10.11.12.13:5410 scanned my UDP ports from myip:5210 to myip:5230 ports(5211,5212,5213,5214.......5228,5229,5230) And my UDP port was 2271.

My router brand is zyxel. Today I called their support to ask if a configuration from router is needed or not, to block these scannings, and they said that my router's firewall blocks all unauthorised connections by default and no need to change anything. But for extra security I'll setup pfsense firewall after some research.

Well if they had hit a port that you were forwarding, then most likely it wouldn't even be logged. Your router is just logging noise, ie stuff it blocked. Yes pfsense does the same thing. Unless you turn it off, all blocks will be logged.

I created a specific rule at the bottom of my list to block UDP before it gets to the default rule, just so it is not logged.. It fills up the logs all the noise.. I would be more curious to what tcp ports they are trying to hit vs UDP noise, which is most likely p2p traffic stuff.

So I am curious on your pfsense setup, did you put it behind your current router? If so your double natting? Or did you remove your other router, or put it into bridge mode so pfsense gets a public on its wan?

Hi

I haven't setup pfsense firewall yet. I am currently searching information about pfsense installation and configuration. I am thinking of buying a mini ITX pc that has two ethernet ports.(found one with reasonable price on internet)

If everything goes alright my configuration will be like this:

My current router >> pfsense firewall >> switch >> wireless router or directly to computer or both

So your current router is actually a gateway? it has a modem in it? Your going to put it in bridge mode?

If not what is the point of that in the path?

And when you say wireless router, you mean wireless router used as Acesspoint?

If I understand it correct, zyxel's mode is currently Routing and also has bridge mode.(I am adsl user and only with Routing mode I can login to my isp)

"And when you say wireless router, you mean wireless router used as Acesspoint?"

Actually I didn't think about acesspoint.

I don't know if wireless router work as acesspoint or not, so there is no need to take the risk and confusing setup process. Acesspoint will be better for me, right? (ZYXEL WAP3205, LINKSYS WAP610N or something like like these devices?)

This topic is now closed to further replies.
  • Posts

    • Opinion. All you did was blame Democrats for everything. You offered nothing but a hit piece to support your pro Trump, anti union right wing ideology.
    • Excuse me for having an opinion, fella'... (Why am I not surprised?...) Congrats on your very informative post however...
    • By the sounds of that wall of Fox News propaganda gibberish attacking the Democratic Party you've already had plenty of "juices" flowing this morning. You've ruined what could have been a productive comment thread.
    • (Topic to get the juices flowing this Sunday morning!...) Actually, the situation has almost nothing to do with "lack of skills", especially since assembly-line skills can be taught to anyone, including Americans, certainly. Rather, the inadequacy-to-impossibility of large-scale tech manufacturing in America today, and the reasons why America finds tech manufacturing completely onerous in the 21st century, has to do with politically driven laws amid a plethora of non-scientific, utterly politicized "science-fact" that is patently false, punitive business taxation at every turn, an array of judicial fines of unimaginable scope and complexity, and, last but not least, American unionization strictures that serve to actually slay job creation and hobble all such manufacturing endeavors in America before they can get off the ground. Globalism emerged, they tell us, as the needed answer to American hubris and an unholy American drive to excel. Unless one is buried under mounds of political propaganda, it's easy to see the absurdity of labeling the employees of SpaceX, for instance, as "unskilled labor"... Etc. ad infinitum. At one time in the recent past, American manufacturing prowess was the envy of the world in a wide variety of technical fields! The current federal and state government roadblocks against America becoming competitive globally in tech manufacturing are considerable, it's true, as anyone with a working brain knows. But remarkably, that is only half the story! The other half of the story is, of course, the corporations themselves... Chinese tech manufacturing is simply unassailable in terms of profits, because the Chinese government wants to see its tech manufacturing second-to-none globally so that no companies/nations can compete in terms of ROI, and China has completely succeeded in that goal. Let's tic-off a few things: *Chinese tariff policies are set according to what is considered best for Chinese business, Chinese employees, and the Chinese people. Huge difference with how things are done with tariffs in the US--as the US government (SCOTUS in this case, Congress in others) plainly feels that tariffs are "unfair" for the limited number of citizens who may pay them, whereas nothing is "unfair" when Congress considers the Personal Income Tax rates to be infinitely hike-able, along with infinitely enlarging annual budget deficits. *The Chinese government boldly subsidizes Chinese companies to artificially amplify their profits. *The Chinese government deliberately refuses to avidly demonize Chinese businesses and does not consider Chinese businesses "the enemy", so very unlike American (D)s these days. *Chinese labor laws and businesses are allowed to set their own labor policies according to what Chinese companies consider is best for companies and their employees... Simply put, American workers in tech manufacturing are not allowed to set their own labor policies! * One additional problem corporations have that I also do not sympathize with is they don't want to pay to train their American employees. They could easily do so, but would rather not have to pay for it. I find that pathetic, actually. It is the height of hypocrisy for Americans to decry working conditions in China while simultaneously ensuring that American products are manufactured in China, not in the US, simply to maximize profits. There is nothing wrong with making a profit, of course, absolutely nothing. But there is plenty wrong with attempts to normalize hypocrisy of this kind! But rank hypocrisy and the (D) party in the US are longtime bedfellows... The current government in Washington is working overtime to see if it can toss out the horribly poor, failed economic policies of the past, while the (D)s still in Washington work very hard to bring back the stupidity whenever possible. With the right policies in place, America can be an infinitely competitive manufacturer.
  • Recent Achievements

    • Conversation Starter
      jessse3334 earned a badge
      Conversation Starter
    • Reacting Well
      JuvenileDelinquent earned a badge
      Reacting Well
    • One Month Later
      Excellence2025 earned a badge
      One Month Later
    • Week One Done
      Excellence2025 earned a badge
      Week One Done
    • Week One Done
      flexorcist earned a badge
      Week One Done
  • Popular Contributors

    1. 1
      +primortal
      508
    2. 2
      +Edouard
      198
    3. 3
      PsYcHoKiLLa
      152
    4. 4
      Steven P.
      73
    5. 5
      FloatingFatMan
      62
  • Tell a friend

    Love Neowin? Tell a friend!