What's new

Asus Merlin Iptables to Secure My Network

  • SNBForums Code of Conduct

    SNBForums is a community for everyone, no matter what their level of experience.

    Please be tolerant and patient of others, especially newcomers. We are all here to share and learn!

    The rules are simple: Be patient, be nice, be helpful or be gone!

oOMrYairOo

Regular Contributor
Hello, I have ax88u running the latest merlin, I want to secure whit iptables to block all UDP port scanners out there simply to drop UDP SYN and etc bots, how can I achieve this?
 
SYN is a TCP flag. It does not exist for UDP.

Almost all port scanners are TCP.

The router's firewall drops all unsolicited connections by default.

Firewall > General >Enable DoS protection will block certain TCP flag combinations.

with not whit.
 
Last edited:
ok but let's say i open sip port 5060 UDP how i can hide it from UDP scanners, if I open 5060 USD and test it whit shodan then I get results from shodan that port 5060 UDP is open.
 
ok but let's say i open sip port 5060 UDP how i can hide it from UDP scanners
The only way to do that would be to specify an allowed source address in your port forwarding rule so that everything else is dropped.

with not whit.
 
Close everything and allow only originated traffic. If you originate an outbound session to UDP:5060 then on the return path your system should allow the traffic back into your network.
 

Latest threads

Support SNBForums w/ Amazon

If you'd like to support SNBForums, just use this link and buy anything on Amazon. Thanks!

Sign Up For SNBForums Daily Digest

Get an update of what's new every day delivered to your mailbox. Sign up here!
Top