Hello,
I’m a relative newcomer to RouterOS. I’ve had the CCR 1009-7G-1C-PC and several hAP AC for some time, but have only been using minimal configs.
Recently I had some trouble with the CCR not responding to a login from Winbox, so I did a “hard” reset and re-built the configuration. This time I decided to learn a little more about it.
After that long windup, my question is:
I disabled most common services except for a “support” group using my inside subnet. It all seems to work fine, but after running a port scan from grc.com , I see that TCP ports 1-6 are closed, but “visible”.
I looked up TCP ports 1-6, and now I wonder why they would be “visible”. Should I disable them? I don’t need access to the router from the WAN side, so I would prefer if it the router was as “invisible” as possible.
I also saw that outside ICMP pings were still allowed in many of the firewall configurations. Since my router protects a small business and I do all the maintenance, is there a reason I would want to have ICMP enabled?
Thanks!
-audioguy