DrayTek UK Users' Community Forum

Help, Advice and Solutions from DrayTek Users

Block Port 443

  • dazeck
  • Topic Author
  • User
  • User
More
26 Aug 2018 00:34 #1 by dazeck
Block Port 443 was created by dazeck
I have disabled remote management from the internet, but port 443 is still open. We need to be PCIS compliant and I have to schedule scans of our IP address, but they keep failing as port 443 is self signed so I just want to block port 443 so it isn't seen as open by the scanner. Why is it still listening on port 443 despite me turning off remote management from internet ?

Please Log in or Create an account to join the conversation.

  • bookit
  • User
  • User
More
26 Aug 2018 07:10 #2 by bookit
Replied by bookit on topic Re: Block Port 443
It does this for SSL VPNs. I've changed my SSL VPN port to a high random port that does not show on standard port scans, however 2860 still leaves 443 open. I NAT port 80 and 443 to non existing internal IPs so they don't appear on a port scan.

Please Log in or Create an account to join the conversation.

  • anaglypta
  • User
  • User
More
26 Aug 2018 10:23 #3 by anaglypta
Replied by anaglypta on topic Re: Block Port 443
Hello dazeck

If I probe port 443 it returns STEALTH for me.

You need to untick several options to achieve this

System Maintenance > Management > Untick "Allow Management from the Internet" Untick "Enable SSL 3.0" (should be using TLS these days :) )
VPN and Remote Access > Remote access Control > Untick "Enable SSL VPN Service"

John.

Please Log in or Create an account to join the conversation.

  • dazeck
  • Topic Author
  • User
  • User
More
26 Aug 2018 11:45 #4 by dazeck
Replied by dazeck on topic Re: Block Port 443

Anaglypta wrote:
System Maintenance > Management > Untick "Allow Management from the Internet" Untick "Enable SSL 3.0" (should be using TLS these days :) )



Yeh already done this, that was the easy one to find.

Anaglypta wrote:
VPN and Remote Access > Remote access Control > Untick "Enable SSL VPN Service"



That was the one I was missing, top man, thanks for that. I am now seen as closed on 443 so we should pass the scan now.

Thanks again
Darren

Please Log in or Create an account to join the conversation.