dslreports logo
Search similar:


uniqs
142
jas_dw
Premium Member
join:2004-07-02
Boulder Creek, CA

jas_dw

Premium Member

[DW6000] [DW6000] DSLR port scanning expectations

Hello everyone:

I'm a new DirecWay user and I've been lurking on this forum for a few weeks. A couple weeks ago I had the DW6000 system installed, and I'm generally happy with it. There has been some down time (NOC weather) and the upload speed is pretty lame, but overall it has been working okay.

Having recently signed up at DSL Reports, I came across the Secure-me slow port scan test. I figured I'd like to see how having an always on connection exposes my systems to the world at large. My prior connection was via plain old dialup and ISDN (kind of flaky as well as expensive).

My DW6000 is the home/consumer version where I do not have a static IP address. But, looking at the DW6000 system info screen via my browser, it looks like the "NAT IP Address" (67.143.x.x) has remained the same for quite some time. Is that the address via which others on the internet could attempt to access my computers?

I fired off the DSLR secure-me port scan and it put the test on hold because the IP address I indicated to be scanned (The NAT IP Address above), was not the same as that used when I requested the test via the browser. I had to telnet to dslreports.com and enter my ticket number to confirm. There it said the address I was connecting from was indeed the DW6000 NAT IP Address and the test was allowed to run. Is there some kind of browser proxy in play at DirecWay? My DW6000 does have "Turbo Page" enabled.

Anyway, the port scan results are pretty grim, giving me a score around -1700 or so. It claims that numerous TCP ports are open. I had all sharing turned off on the two Macs on the network and their (Mac OS X) firewalls not allowing anything in. I also re-ran the test with my new Linksys WRT54G router/WAP in place and got the same results.

According to the DSLR FAQs, a port (TCP and UDP) can be considered open if the packets are absorbed w/o an explicit rejection. Is this what happens at the DW6000 or somewhere deeper in the DirecWay NOC infrastructure? In the slow scan queue I see others getting test results of 0 or -30 or something, but my -1700 sticks out like a sore thumb! Should I expect such a score, and be safe?

I'm curious what other DW6000 owners have experienced. Is this normal?

Many thanks!

Jeff
TenKTrees
join:2003-10-25
Willits, CA

TenKTrees

Member

Re: [DW6000] [DW6000] DSLR port scanning expectati

said by jas_dw:

According to the DSLR FAQs, a port (TCP and UDP) can be considered open if the packets are absorbed w/o an explicit rejection.
Personally, I feel that it is far more secure to silently drop unwanted packets than to tell attackers that they have reached a valid IP address. So, I also get -1700 on that test, and feel quite safe, because I know that my firewall is doing exactly what I told it to do.
jas_dw
Premium Member
join:2004-07-02
Boulder Creek, CA

jas_dw

Premium Member

Re: [DW6000] [DW6000] DSLR port scanning expectations

I agree that the silent approach is better; why let them know there is something out there to keep banging away at? Glad to hear that -1700 or so is normal for the DW6000 and not something on my end.

Thanks,

Jeff