 batsonaMaryland join:2004-04-17 Ellicott City, MD Reviews:
·Vonage
·Verizon FiOS
| [Northeast] All these ports are open? I just port-scanned myself from my workplace network. I used the range 22-1024. My Actiontec saw, and dropped traffic on the following ports.... I thought residential FIOS was more locked down than this?
21 22 23 110 220 389 481 989 1023 1024
I'm looking to set up a single-use VPN for me to use, to get into my home network, and I was fretting that VZ was stingy on what it allowed through. -apparently not so? |
|
 hubrisnxs join:2009-12-30 Fountain Valley, CA kudos:1 | res fios only has outbound port 25 closed down, and then port 80 is questionable but mostly open throughout.
other than that, it's wide open baby! |
|
 ThinkdiffPremium,MVM join:2001-08-07 Bronx, NY kudos:6 | reply to batsona I'm running a lot more than a single VPN connection on my residential FiOS connection with no issues. Mail, HTTP (on port 80), SSH, OpenVPN, etc.
My traffic is pretty light (everything is for personal/family use), so I doubt my usage is any concern to VZ -- University of Southern California - Fight On! |
|
 htin11 join:2000-08-10 Flushing, NY | reply to batsona i think it depends on which area, the nyc area has a lot of ports closed off. 25 and 80. |
|
 batsonaMaryland join:2004-04-17 Ellicott City, MD | reply to batsona I should clarify that I was scanning from my workplace, inbound into my FiOS. I notice I didn't see 25, or 80 or 443, but as you can see, a bunch of others are open.
I just need to pick a port for IPSEC to use & I'll be set. |
|
|
|
 ThinkdiffPremium,MVM join:2001-08-07 Bronx, NY kudos:6 | reply to htin11 said by htin11:i think it depends on which area, the nyc area has a lot of ports closed off. 25 and 80. Port 80 is open in The Bronx.. Not sure why it wouldn't be open elsewhere in NYC. -- University of Southern California - Fight On! |
|
 bgraham join:2001-03-15 Smithtown, NY Reviews:
·VOIPo
·Verizon VoiceWing
| reply to batsona
I have no ports open in Suffolk County. I did a router factory reset a couple of months ago because of ongoing VOIP issues. Never bothered to turn off reply to pings. |
|
 | That's not the correct Test, it's used for checking NAT and firewall Security. You should be using The ICSI Netalyzr From UC Berkeley. It test's everything from dns to buffer bloat and open port's.
»netalyzr.icsi.berkeley.edu/ |
|
 rchandraStargate Universe fanPremium join:2000-11-09 14225-2105 | reply to batsona IPSec itself doesn't use your concept of port anyway. It uses a different protocol number (it's 50 or 51, depending on implementation...although usually 50 because AH at 51 doesn't NAT at all). Despite sooooooooooo many people using the term "TCP/IP," it's massively incorrect. Although admittedly the majority of IP traffic is TCP, there's plenty which use other protocols. (although...With increasing uptake of VoIP and other streamed protocols, more and more traffic is UDP.)
In particular, you're going to want to see if UDP port 500 is open for IKE. I can't imagine why they'd choose to block that. If you're using the UDP encapsulating flavor of IPSec, you're going to want to see if UDP port 4500 is open. See also RFC 3948, which deals with encapsulating IPSec in UDP to make NAT easier though not foolproof.
Besides...if you haven't done so already, I would seriously consider delving into the resources on this site with regards to putting the Actiontec into bridging mode and using your own router. Therefore you don't have to rely on what it thinks is or is not good, or will or will not NAT. The only thing at that point you'd have to worry about is what Verizon might filter before packets even get to your ONT.
Something you may wish to consider: that you didn't know this might give your other (non home) endpoint some concern about the security of their internal network.
-- English is a difficult enough language to interpret correctly when its rules are followed, let alone when a writer chooses not to follow those rules.
Jeopardy! replies and randomcaps REALLY suck! |
|
 batsonaMaryland join:2004-04-17 Ellicott City, MD Reviews:
·Vonage
·Verizon FiOS
| I left out an important detail.. I'll be using the Cisco VPN Concentrator (yes, it's end-of-life this summer).. it has the capability of moving IPSEC onto a regular old TCP port, instead of using ESP / protocol 50 or 51. Slightly wider compatibility this way, in case people are indeed blocking 50 or 51. IKE, as well as the tunnel itself will use this TCP port. |
|