I have a problem with ASUS RT-AC68U:
1. After installing ASUS firmware 3.0.0.4.386.49703 I could not access web GUI anymore. Did reset factory defaults and configured, everything seemed to be ok.
2. Sometime later noticed, that web GUI was again unreachable, so repeated #1.
3. Sometime later Web GUI became unreachable again.
4. Did reset factory defaults, but did not configure more than just get the GUI up.
5. Loaded Asuswrt RT-AC68U_386.7_2.trx and configured, all seemed to be ok.
6. Next day opened the GUI and rebooted from there just to be sure, that all is still ok. GUI indicated applying settings for quite some time, which was weird, because I had not made any changes with GUI.
7. After reboot GUI was again unreachable, so I tested with nmap TCP SYN scanning ports 1-65535. Nmap found these TCP ports open: 53, 7788 and 18017.
What is going on?
TCP port 7788 seems to be used by some trojans, so do I have malware somewhere in LAN? Capable of hacking the router?
Edit: Router is in AP mode and behind pfSense firewall.
1. After installing ASUS firmware 3.0.0.4.386.49703 I could not access web GUI anymore. Did reset factory defaults and configured, everything seemed to be ok.
2. Sometime later noticed, that web GUI was again unreachable, so repeated #1.
3. Sometime later Web GUI became unreachable again.
4. Did reset factory defaults, but did not configure more than just get the GUI up.
5. Loaded Asuswrt RT-AC68U_386.7_2.trx and configured, all seemed to be ok.
6. Next day opened the GUI and rebooted from there just to be sure, that all is still ok. GUI indicated applying settings for quite some time, which was weird, because I had not made any changes with GUI.
7. After reboot GUI was again unreachable, so I tested with nmap TCP SYN scanning ports 1-65535. Nmap found these TCP ports open: 53, 7788 and 18017.
What is going on?
TCP port 7788 seems to be used by some trojans, so do I have malware somewhere in LAN? Capable of hacking the router?
Edit: Router is in AP mode and behind pfSense firewall.