Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Open port 7547?

    Scheduled Pinned Locked Moved General pfSense Questions
    11 Posts 4 Posters 625 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • V
      viragomann @WhoAmI68
      last edited by

      @WhoAmI68
      I don't expect any port to be open, apart from which you explicitly forwarded to a host behind or that ones used by pfSense itself.

      To find out, if it's used by pfSense run

      sockstat | grep .7547
      
      W 1 Reply Last reply Reply Quote 0
      • W
        WhoAmI68 @viragomann
        last edited by

        @viragomann
        I only use the command prompt, so the output is null.
        command prompt.png

        Anyway, scan from the outside
        Port7547.png

        V 1 Reply Last reply Reply Quote 0
        • V
          viragomann @WhoAmI68
          last edited by

          @WhoAmI68
          Get sure, that the test even tries to access this port on your WAN.

          Use packet capture to sniff the traffic on WAN, while you run the test.

          W 3 Replies Last reply Reply Quote 0
          • stephenw10S
            stephenw10 Netgate Administrator
            last edited by

            Could be the ISP device. Does pfSense actually have a public IP on it's WAN?

            W 1 Reply Last reply Reply Quote 0
            • W
              WhoAmI68 @viragomann
              last edited by

              This post is deleted!
              1 Reply Last reply Reply Quote 0
              • W
                WhoAmI68 @viragomann
                last edited by

                @viragomann It is a very interesting thing about Sniff :).

                Nmap from different networks will be null and Captive portal the same
                Capture.png

                Pf logs is zero but When I use dnschecker.org or ipfingerprints.com, the result is as follows
                check.png

                1 Reply Last reply Reply Quote 0
                • W
                  WhoAmI68 @stephenw10
                  last edited by

                  @stephenw10 said in Open port 7547?:

                  Does pfSense actually have a public IP on it's WAN?

                  Yes, pfsense have a public IP on WAN :).

                  1 Reply Last reply Reply Quote 0
                  • W
                    WhoAmI68 @viragomann
                    last edited by

                    @viragomann Correction: Nmap scan is dropped by Suricata.

                    log: 10/29/2024 17:11:37 GPL SCAN PING NMAP

                    1 Reply Last reply Reply Quote 0
                    • stephenw10S
                      stephenw10 Netgate Administrator
                      last edited by

                      Assuming your WAN actually has a public IP then it looks like something upstream is redirecting traffic on that port.

                      johnpozJ 1 Reply Last reply Reply Quote 0
                      • johnpozJ
                        johnpoz LAYER 8 Global Moderator @stephenw10
                        last edited by

                        @stephenw10 exactly 7547 is the TR-069 service.

                        "is a bidirectional SOAP/HTTP-based protocol that provides communication between CPE devices and auto-configuration servers (ACS)."

                        Would seem quite possible that the isp device, ie the CPE is using this.

                        https://en.wikipedia.org/wiki/TR-069

                        An intelligent man is sometimes forced to be drunk to spend time with his fools
                        If you get confused: Listen to the Music Play
                        Please don't Chat/PM me for help, unless mod related
                        SG-4860 24.11 | Lab VMs 2.8, 24.11

                        1 Reply Last reply Reply Quote 2
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.