Community discussions

MikroTik App
 
jerresnow
just joined
Topic Author
Posts: 1
Joined: Thu Oct 05, 2023 6:29 pm

open port vs forward port

Wed Oct 11, 2023 10:02 pm

I have a problem with a device/receiver (wegener i8640) at a radio station. They request these four ports to be open: 80,443,123,53. If I forward them to the device, only 80 show as open, but that exposes the editable status page of the receiver to the world on the public IP. How do I configure the firewall to be open for incoming without exposing the status page to the world? I won't go into all the things I've tried, but need help.
 
User avatar
BartoszP
Forum Guru
Forum Guru
Posts: 2880
Joined: Mon Jun 16, 2014 1:13 pm
Location: Poland

Re: open port vs forward port

Thu Oct 12, 2023 3:11 am

It's an oxymoron ...opening port for the world not opening it for the world.

No clue what port 123 (NTP) or 53 (DNS) should be opened (redirected to the device) for?
 
rplant
Member
Member
Posts: 314
Joined: Fri Sep 29, 2017 11:42 am

Re: open port vs forward port

Tue Oct 17, 2023 12:14 pm

My guess (but I could well be wrong...)

They want access to the outside internet using these ports.
So remove the inbound port forwards.

If keen (and possibly not a terrible option), you could block (and log) all other outbound access.
 
pe1chl
Forum Guru
Forum Guru
Posts: 10248
Joined: Mon Jun 08, 2015 12:09 pm

Re: open port vs forward port

Tue Oct 17, 2023 12:22 pm

Yes, many devices list "open port requirements" for access they want TO the internet.
But in most default configurations of routers with connection-tracking firewall (like MikroTik), ALL ports are already open outbound.
So there is nothing you need to change on the router.

It is unfortunate that publishing these requirements leads to action (opening ports from outside to inside) that actually makes the configuration unsafe...

Who is online

Users browsing this forum: mqa87it, Semrush [Bot] and 17 guests