Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Open port 7547?

    Scheduled Pinned Locked Moved General pfSense Questions
    11 Posts 4 Posters 590 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • W
      WhoAmI68
      last edited by

      Hi all,
      ISP has router in bridge mode.
      I closed all ports on the WAN during the test but When I check the port 7547 of the outsize, it is open.

      How is that possible, or am I something that I do not understand?
      Thanks for help.

      V 1 Reply Last reply Reply Quote 0
      • V
        viragomann @WhoAmI68
        last edited by

        @WhoAmI68
        I don't expect any port to be open, apart from which you explicitly forwarded to a host behind or that ones used by pfSense itself.

        To find out, if it's used by pfSense run

        sockstat | grep .7547
        
        W 1 Reply Last reply Reply Quote 0
        • W
          WhoAmI68 @viragomann
          last edited by

          @viragomann
          I only use the command prompt, so the output is null.
          command prompt.png

          Anyway, scan from the outside
          Port7547.png

          V 1 Reply Last reply Reply Quote 0
          • V
            viragomann @WhoAmI68
            last edited by

            @WhoAmI68
            Get sure, that the test even tries to access this port on your WAN.

            Use packet capture to sniff the traffic on WAN, while you run the test.

            W 3 Replies Last reply Reply Quote 0
            • stephenw10S
              stephenw10 Netgate Administrator
              last edited by

              Could be the ISP device. Does pfSense actually have a public IP on it's WAN?

              W 1 Reply Last reply Reply Quote 0
              • W
                WhoAmI68 @viragomann
                last edited by

                This post is deleted!
                1 Reply Last reply Reply Quote 0
                • W
                  WhoAmI68 @viragomann
                  last edited by

                  @viragomann It is a very interesting thing about Sniff :).

                  Nmap from different networks will be null and Captive portal the same
                  Capture.png

                  Pf logs is zero but When I use dnschecker.org or ipfingerprints.com, the result is as follows
                  check.png

                  1 Reply Last reply Reply Quote 0
                  • W
                    WhoAmI68 @stephenw10
                    last edited by

                    @stephenw10 said in Open port 7547?:

                    Does pfSense actually have a public IP on it's WAN?

                    Yes, pfsense have a public IP on WAN :).

                    1 Reply Last reply Reply Quote 0
                    • W
                      WhoAmI68 @viragomann
                      last edited by

                      @viragomann Correction: Nmap scan is dropped by Suricata.

                      log: 10/29/2024 17:11:37 GPL SCAN PING NMAP

                      1 Reply Last reply Reply Quote 0
                      • stephenw10S
                        stephenw10 Netgate Administrator
                        last edited by

                        Assuming your WAN actually has a public IP then it looks like something upstream is redirecting traffic on that port.

                        johnpozJ 1 Reply Last reply Reply Quote 0
                        • johnpozJ
                          johnpoz LAYER 8 Global Moderator @stephenw10
                          last edited by

                          @stephenw10 exactly 7547 is the TR-069 service.

                          "is a bidirectional SOAP/HTTP-based protocol that provides communication between CPE devices and auto-configuration servers (ACS)."

                          Would seem quite possible that the isp device, ie the CPE is using this.

                          https://en.wikipedia.org/wiki/TR-069

                          An intelligent man is sometimes forced to be drunk to spend time with his fools
                          If you get confused: Listen to the Music Play
                          Please don't Chat/PM me for help, unless mod related
                          SG-4860 24.11 | Lab VMs 2.8, 24.11

                          1 Reply Last reply Reply Quote 2
                          • First post
                            Last post
                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.