What's new

[CRITICAL BUG] Merlin SSH and WEB on WAN always enabled !!!

  • SNBForums Code of Conduct

    SNBForums is a community for everyone, no matter what their level of experience.

    Please be tolerant and patient of others, especially newcomers. We are all here to share and learn!

    The rules are simple: Be patient, be nice, be helpful or be gone!

always allows SSH and Web admin interface connections through WAN EVEN IF I have disabled those WAN accesses !!!!!!!!

(1) You need to test this from truly outside of your LAN (the router is smart enough to know that if you are using your external address or DDNS name from within your LAN, that you are really local)
(2) Make sure that the router firewall is enabled. If you disable the firewall, the entire network/router becomes open to the internet regardless of any other settings.
 
(1) You need to test this from truly outside of your LAN (the router is smart enough to know that if you are using your external address or DDNS name from within your LAN, that you are really local)
(2) Make sure that the router firewall is enabled. If you disable the firewall, the entire network/router becomes open to the internet regardless of any other settings.

I am totaly outside, 100 Km far, thrugh 4G connection.

about the secondo point....... firewall infact is disabled, i am going to enable it right now....in any case.... is it not crazy that with firewall disabled, the router does esposes those ports ?
 
about the secondo point....... firewall infact is disabled, i am going to enable it right now....in any case.... is it not crazy that with firewall disabled, the router does esposes those ports ?
Not really....what happens if you disable the Windows firewall for example...the same thing. If you disable the firewall it's probably for debug purposes and you don't want it to be interfering at all.

Now, IMHO, the router could be a little more explicit in warning you about what will happen if you disable the firewall. I just added a banner alert and pop-up warning to my fork if you do this.
 
1) Disabling the firewall means you are voluntarily exposing your whole router to the WAN. Nothing crazy about it, the crazy part is running a router with its firewall disabled, quite frankly.

2) Interface binding has been changed by Asus months ago, so services now bind to specific interfaces rather than all interfaces by default. You need to upgrade, this was changed in 380.59, with that build you need to explicitly enable WAN access for various services such as SSH to listen to the WAN interface.

how to solve this crazy bug ?

By upgrading to 380.59.
 

Similar threads

Latest threads

Support SNBForums w/ Amazon

If you'd like to support SNBForums, just use this link and buy anything on Amazon. Thanks!

Sign Up For SNBForums Daily Digest

Get an update of what's new every day delivered to your mailbox. Sign up here!

Members online

Top