I have a very weird situation in which 3389 port goes through the routers, even if not forwarded / enabled. I have had to make a specific firewall rule to block the port!
Can you please take a look what I did wrong?
add action=accept chain=input comment="defconf: accept established,related,untracked" connection-state=established,related,untracked
add action=accept chain=input comment="L2TP allow only with IPsec" dst-port=1701 in-interface=ether10-WAN ipsec-policy=in,ipsec protocol=udp
add action=drop chain=input comment="Drop L2TP without IPsec" dst-port=1701 in-interface=ether10-WAN protocol=udp
add action=accept chain=input comment="L2TP allow" dst-port=500,4500 in-interface=ether10-WAN protocol=udp
add action=accept chain=input comment="IPSec enable" in-interface=ether10-WAN protocol=ipsec-esp
add action=drop chain=input comment="defconf: drop invalid" connection-state=invalid
add action=accept chain=input comment="defconf: accept ICMP" protocol=icmp
add action=drop chain=input comment="defconf: drop all not coming from LAN" in-interface=ether10-WAN
add action=accept chain=forward comment="defconf: accept in ipsec policy" ipsec-policy=in,ipsec
I HAVE DISABLED THIS; AND THE 3389 STILL GOES THRU add action=accept chain=forward comment="RDP accept and forward to 192.168.10.3" disabled=yes dst-address-list=192.168.10.3 dst-port=3389 in-interface=ether10-WAN protocol=tcp
add action=accept chain=forward comment="defconf: accept out ipsec policy" ipsec-policy=out,ipsec
add action=fasttrack-connection chain=forward comment="defconf: fasttrack" connection-state=established,related
add action=accept chain=forward comment="defconf: accept established,related, untracked" connection-state=established,related,untracked
add action=drop chain=forward comment="defconf: drop invalid" connection-state=invalid
add action=drop chain=forward comment="drop unvanted local traffic" connection-nat-state=!dstnat connection-state=new in-interface=ether10-WAN
add action=drop chain=forward in-interface=bridge-local out-interface=bridge-ivana
add action=drop chain=forward in-interface=bridge-ivana out-interface=bridge-local
add action=drop chain=forward in-interface=all-wireless out-interface-list=LAN
add action=drop chain=forward in-interface-list=LAN out-interface=all-wireless
THIS ONE I ADDED TO BLOCK 3389 add action=drop chain=forward comment="explicitly drop 3389 in" disabled=yes dst-port=3389 in-interface=ether10-WAN protocol=tcp