You can make a difference in the Apple Support Community!

When you sign up with your Apple Account, you can provide valuable feedback to other community members by upvoting helpful replies and User Tips.

Looks like no one’s replied in a while. To start the conversation again, simply ask a new question.

Can TC ports be stealthed to ShieldsUP?

TC, running 7.9.1 firmware, wired directly to cable modem. AirPort Utility 6.3.9 on Mojave connecting over WiFi to TC.


Right now, ShieldsUP shows everything "closed" except for 139, 445, and 548, which are "open." GRC reports those as 139 (NetBIOS Session Service), 445 (Microsoft Directory Service), and 548 (AFP over TCP), although I understand that may not be what macOS is doing with them.


Are there any TC settings that would close 139, 445, and 548 (or any of them)?

Is there any way to "stealth" ports using a TC?


TIA,


Mark

Posted on Nov 1, 2019 4:02 PM

Reply
Question marked as Top-ranking reply

Posted on Nov 1, 2019 9:46 PM

UPDATE: Somehow, "Disks .. Share disks over WAN" had been checked.


Yeah.. that is the one. Good work.. and I should have twigged by AFP being open.


It is why we always recommend people do a factory reset when they change setup to make sure everything goes back to defaults.. in any new situation.


So, my remaining questions are, why does Network Utility show some as "open," and can I get TC to stealth them?

You don't need to worry about the other ports open.. they are open from LAN side not WAN side.. so you are now fully shut off to outside world. At least AFAIK for IPv4. You cannot check directly to WAN from Network Utility.

3 replies
Question marked as Top-ranking reply

Nov 1, 2019 9:46 PM in response to Mark92630

UPDATE: Somehow, "Disks .. Share disks over WAN" had been checked.


Yeah.. that is the one. Good work.. and I should have twigged by AFP being open.


It is why we always recommend people do a factory reset when they change setup to make sure everything goes back to defaults.. in any new situation.


So, my remaining questions are, why does Network Utility show some as "open," and can I get TC to stealth them?

You don't need to worry about the other ports open.. they are open from LAN side not WAN side.. so you are now fully shut off to outside world. At least AFAIK for IPv4. You cannot check directly to WAN from Network Utility.

Nov 1, 2019 5:29 PM in response to Mark92630

Is your TC in bridge or router mode?

Or

asking the question another way, is your cable modem a pure modem.. ie it has only one ethernet port, or you asked and confirmed the ISP has bridged a modem router.

Or

another way to ask is what IP do you have on the WAN port of the TC? Is it a private IP like 10.x.x.x or 192.168.x.x


This is important so we know it is really the TC issue and not the main router.


I am guessing you have a pure modem and the TC is your main router and has the public IP on the WAN.


The next question is IPv6. Are you using it, as it might affect the way ports are showing.

I am surprised 548 is open to WAN.. by default that is not the case. Nor should the other two ports but in PC world they are hard to hide.


Is there an error showing on the airport utility summary page of your TC? Perhaps you can post that screenshot.. if you have a public IP just cover the last few digits. I have mine in double NAT.. but it should not have any ports open to internet.



Setup over WAN is a bad one.. and should be off.


Let me check this from network utilities. No ports are open in standard NAT mode.


Nov 1, 2019 9:24 PM in response to LaPastenague

Router.

-or-

Only one port. My new ISP provided a separate router, which I am seeking to replace with my old TC.

-or-

Not private: 164.68.1xx.xxx


IPv6 - I don't know. I'm certainly not trying to use it. "Internet Options..." are to Configure IPv6 "Automatically" and IPv6 Mode is "Native" and IPv6 Connection Sharing is Enabled (checked). The rest of that page is blank. And "Block incoming IPv6 connections" is a Network Option...


No errors from AU; green lights for both Internet and TC.



Allow setup over WAN is off.


From Network Utility:



UPDATE: Somehow, "Disks .. Share disks over WAN" had been checked. When I unchecked it, ShieldsUP now shows all ports as "closed". So, my remaining questions are, why does Network Utility show some as "open," and can I get TC to stealth them?








Can TC ports be stealthed to ShieldsUP?

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.