• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Open port 7547?

General pfSense Questions
4
11
563
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • W
    WhoAmI68
    last edited by Oct 29, 2024, 2:56 PM

    Hi all,
    ISP has router in bridge mode.
    I closed all ports on the WAN during the test but When I check the port 7547 of the outsize, it is open.

    How is that possible, or am I something that I do not understand?
    Thanks for help.

    V 1 Reply Last reply Oct 29, 2024, 3:34 PM Reply Quote 0
    • V
      viragomann @WhoAmI68
      last edited by Oct 29, 2024, 3:34 PM

      @WhoAmI68
      I don't expect any port to be open, apart from which you explicitly forwarded to a host behind or that ones used by pfSense itself.

      To find out, if it's used by pfSense run

      sockstat | grep .7547
      
      W 1 Reply Last reply Oct 29, 2024, 3:57 PM Reply Quote 0
      • W
        WhoAmI68 @viragomann
        last edited by Oct 29, 2024, 3:57 PM

        @viragomann
        I only use the command prompt, so the output is null.
        login-to-view

        Anyway, scan from the outside
        login-to-view

        V 1 Reply Last reply Oct 29, 2024, 3:59 PM Reply Quote 0
        • V
          viragomann @WhoAmI68
          last edited by Oct 29, 2024, 3:59 PM

          @WhoAmI68
          Get sure, that the test even tries to access this port on your WAN.

          Use packet capture to sniff the traffic on WAN, while you run the test.

          W 3 Replies Last reply Oct 29, 2024, 4:38 PM Reply Quote 0
          • S
            stephenw10 Netgate Administrator
            last edited by Oct 29, 2024, 4:04 PM

            Could be the ISP device. Does pfSense actually have a public IP on it's WAN?

            W 1 Reply Last reply Oct 29, 2024, 4:49 PM Reply Quote 0
            • W
              WhoAmI68 @viragomann
              last edited by Oct 29, 2024, 4:38 PM

              This post is deleted!
              1 Reply Last reply Reply Quote 0
              • W
                WhoAmI68 @viragomann
                last edited by Oct 29, 2024, 4:46 PM

                @viragomann It is a very interesting thing about Sniff :).

                Nmap from different networks will be null and Captive portal the same
                login-to-view

                Pf logs is zero but When I use dnschecker.org or ipfingerprints.com, the result is as follows
                login-to-view

                1 Reply Last reply Reply Quote 0
                • W
                  WhoAmI68 @stephenw10
                  last edited by Oct 29, 2024, 4:49 PM

                  @stephenw10 said in Open port 7547?:

                  Does pfSense actually have a public IP on it's WAN?

                  Yes, pfsense have a public IP on WAN :).

                  1 Reply Last reply Reply Quote 0
                  • W
                    WhoAmI68 @viragomann
                    last edited by Oct 29, 2024, 4:53 PM

                    @viragomann Correction: Nmap scan is dropped by Suricata.

                    log: 10/29/2024 17:11:37 GPL SCAN PING NMAP

                    1 Reply Last reply Reply Quote 0
                    • S
                      stephenw10 Netgate Administrator
                      last edited by Oct 29, 2024, 6:19 PM

                      Assuming your WAN actually has a public IP then it looks like something upstream is redirecting traffic on that port.

                      J 1 Reply Last reply Oct 29, 2024, 6:30 PM Reply Quote 0
                      • J
                        johnpoz LAYER 8 Global Moderator @stephenw10
                        last edited by Oct 29, 2024, 6:30 PM

                        @stephenw10 exactly 7547 is the TR-069 service.

                        "is a bidirectional SOAP/HTTP-based protocol that provides communication between CPE devices and auto-configuration servers (ACS)."

                        Would seem quite possible that the isp device, ie the CPE is using this.

                        https://en.wikipedia.org/wiki/TR-069

                        An intelligent man is sometimes forced to be drunk to spend time with his fools
                        If you get confused: Listen to the Music Play
                        Please don't Chat/PM me for help, unless mod related
                        SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                        1 Reply Last reply Reply Quote 2
                        6 out of 11
                        • First post
                          6/11
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.