What's new

How to enable port randomization in Asuswrt-Merlin?

  • SNBForums Code of Conduct

    SNBForums is a community for everyone, no matter what their level of experience.

    Please be tolerant and patient of others, especially newcomers. We are all here to share and learn!

    The rules are simple: Be patient, be nice, be helpful or be gone!

Yota

Very Senior Member
By default pfSense will port randomize all outgoing UDP connections (reference), which some say indirectly improves the privacy and security of devices behind the firewall.

This basically turns NAT into a more restrictive level. for example, a device behind the LAN wants UDP port 48695 open, but the firewall will actually open another random port, thus improving security at the expense of connectivity.


Although I'm not sure most people who buy Asus routers will actually want this feature, as some people even buy it to reduce their NAT level 😂

So, seriously, I wonder if the firewall on Asuswrt-Merlin can allow us to achieve something similar?
 
Linux has had UDP port randomization in the kernel since 2008.
 
Linux has had UDP port randomization in the kernel since 2008.
Thanks for the reply, the weird thing is that I never had any issues with peer connectivity, even with UDP based VoIP peer calls. I thought port randomization would cause two devices behind NAT to never be able to talk peer to peer and would have to fall back to relay, but no, I never observed my peer Facetime or WhatsApp calls fall back to relay mode.

So is there any way to break peer connectivity? I thought port randomization was the feature I was looking for.
 
So is there any way to break peer connectivity? I thought port randomization was the feature I was looking for.
I have no idea what you are talking about, sorry. Remote ends don't blindly guess what port they are connected with, that is specified in the connection handshake.
 
I have no idea what you are talking about, sorry. Remote ends don't blindly guess what port they are connected with, that is specified in the connection handshake.
I think you've helped point me in the right direction, thank you.
 

Similar threads

Latest threads

Support SNBForums w/ Amazon

If you'd like to support SNBForums, just use this link and buy anything on Amazon. Thanks!

Sign Up For SNBForums Daily Digest

Get an update of what's new every day delivered to your mailbox. Sign up here!
Top