Looks like no one’s replied in a while. To start the conversation again, simply ask a new question.

NAT default open ports

I want to use the NAT firewall of AirPort Express.I scan APE ports when NO ports are forwarded and these ports are open by default:

Open TCP Port: 21 ftp

Open TCP Port: 53 domain

Open TCP Port: 139 netbios-ssn

Open TCP Port: 445 microsoft-ds

Open TCP Port: 548 afpovertcp

Open TCP Port: 554 rtsp

Open TCP Port: 5009 winfs

Open TCP Port: 7070 arcp


My question is why?

And there are some way to close some?


I don't use FTP and other services.

MacBook Air, Mac OS X (10.7)

Posted on Jan 12, 2014 12:22 PM

Reply
Question marked as Best reply

Posted on Jan 12, 2014 5:15 PM

By default, all inbound ports on the Apple routers are closed already, but they are not designed to be stealthy. As such, certain utilities can see them as open.


Please check out the following Chron article. It may be a bit outdated but I think it drives the point across why Apple decided not to make their base station ports stealthy.

5 replies
Question marked as Best reply

Jan 12, 2014 5:15 PM in response to jorost

By default, all inbound ports on the Apple routers are closed already, but they are not designed to be stealthy. As such, certain utilities can see them as open.


Please check out the following Chron article. It may be a bit outdated but I think it drives the point across why Apple decided not to make their base station ports stealthy.

Jan 18, 2014 7:07 AM in response to Tesserax

Security is always important and crucial.What i'd like to know is:

If the benefit of using stealthed ports is NOT RESPONDING of the bots , pretending that there is no services at this IP, than it's a bit usless because it's not possible to stealth open ports which server use.the firewall won't answer at all setalthed ports but will answer about open ones which gives an information that there is working host.

NAT default open ports

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple ID.