Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Ports visible to the world behind Netgate appliance

    Scheduled Pinned Locked Moved Firewalling
    8 Posts 2 Posters 474 Views 2 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M Offline
      MikeHalsey
      last edited by

      Hi all,

      I get great comfort knowing I have my network hidden behind a Netgate 2100 and pfSense+, especially with IoT devices where there's just no way to know when they were last updated, and if they have any vulnerabilities.

      When I do a GRC port scan though two ports, it looks like 89 and 90, are visible, showing as closed by reporting. Previously the entire network showed as stealth. Does anybody have any advice for me on this on maybe anything that could be changed in pfSense to stop these ports reporting?

      I'm on Starlink if it's relevant and helpful. Thanks all.

      Screenshot 2023-11-14 133526.png

      GertjanG 1 Reply Last reply Reply Quote 0
      • GertjanG Online
        Gertjan @MikeHalsey
        last edited by

        @MikeHalsey

        I really want you to do the very same test using the your 2100 device on another site.
        If possible, not a Starlink site.

        What you can do right now :

        Remove your PC from pfSense (LAN port).
        Remove pfSense from the Starlink 'box'
        Attach PC to Startlink box.
        => !! Set the PC network to Public - not Private !! as a Windows PC has a lot of open ports when using Private networking.
        My PC is french, select this one :

        7f8cf30b-6c69-4d13-80c1-fa1492c94f92-image.png

        Do the test again.

        Btw : I presume you have no WAN firewall rules

        No "help me" PM's please. Use the forum, the community will thank you.
        Edit : and where are the logs ??

        M 2 Replies Last reply Reply Quote 0
        • M Offline
          MikeHalsey @Gertjan
          last edited by

          @Gertjan Did that, got a different result by the visible ports before were now in stealth. So it's definitely the Netgate allowing them to show as closed.

          And no, I don't have any firewall rules set with the exception of having my VPN configured in the Netgate.

          Many thanks,

          Mike

          2023-11-14_14-18-22.jpg

          GertjanG 1 Reply Last reply Reply Quote 0
          • M Offline
            MikeHalsey @Gertjan
            last edited by MikeHalsey

            @Gertjan Okay, so I've plugged the Netgate back in and suddenly it's passed the test! I ran it three times just to be sure.

            The second and third time though a different port was showing as closed.

            What could have caused that do you think? 🤔

            2023-11-14_14-27-45.jpg

            2023-11-14_14-30-38.jpg

            1 Reply Last reply Reply Quote 0
            • GertjanG Online
              Gertjan @MikeHalsey
              last edited by

              @MikeHalsey

              Reconnect pfSense.
              Reconnect PC on pfSense LAN.
              Open the pfSense console (also good : ssh) and use menu option 8.

              Execute these two

              sockstat -4 | grep ':89'
              sockstat -4 | grep ':90'
              

              Any hits ?

              and

              sockstat -4
              

              to see every process, and ports & protocols (TCP or UDP) used.

              Btw : be assured : A pfSense just installed is 100 % 'stealth' on its WAN interface == doesn't reply to any request what so ever.

              No "help me" PM's please. Use the forum, the community will thank you.
              Edit : and where are the logs ??

              M 2 Replies Last reply Reply Quote 0
              • M Offline
                MikeHalsey @Gertjan
                last edited by

                @Gertjan Gotta be honest I'm not sure how to do that. I got into the console and chose option 8 (Shell) and 12 (PHP Shell + Netgate psSense Plus Tools) but nothing happened with your commands. Sorry, I'm a UI kind'a guy.

                Mike

                GertjanG 1 Reply Last reply Reply Quote 0
                • M Offline
                  MikeHalsey @Gertjan
                  last edited by

                  @Gertjan And now it's cooperating again suddenly, did several tests. Perhaps it was a blip?! Is there something I can set in the firewall though for extra peace of mind?

                  Thanks for your help

                  2023-11-14_14-27-45.jpg

                  1 Reply Last reply Reply Quote 0
                  • GertjanG Online
                    Gertjan @MikeHalsey
                    last edited by

                    @MikeHalsey said in Ports visible to the world behind Netgate appliance:

                    I got into the console and chose option 8 (Shell)

                    You saw the menu :

                    9c555c32-f3a0-4478-90c9-c078df500430-image.png

                    Type 8 + enter and you have 'full control'.

                    Then you type (copy past) the commands I've shown above.

                    Btw : not really needed now, but keep in mind that the GUI is just a (several !) layers above the 'real' stuff.
                    Even the command line is a layer, but you can use command that can tell you everything about the system.
                    The golden rule appies : if all goes well, you don't need (to access) it.

                    No "help me" PM's please. Use the forum, the community will thank you.
                    Edit : and where are the logs ??

                    1 Reply Last reply Reply Quote 0
                    • First post
                      Last post
                    Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.