Constant port scans on my router WAN (Afrihost on Openserve)

Gimli_

Expert Member
Joined
Feb 8, 2005
Messages
1,077
Reaction score
370
Location
Irene, Centurion
This weekend I spent a good couple of hours staring at my live firewall logs. What I saw was constant port scans from IPs all across the world (Bulgaria, America, Netherlands etc.) Not even scanning random ports, just going down the list like 39000, 39001, 39002 etc. I disconnected for a while to force a new IP address but that did not change, just the source IPs changed.

My firewall drops the packet, it doesn't block the packet (there is a difference).

My question is, should we just live with it and trust our CPE? Or should we be asking our ISPs to implement some algorithm to identify port scans and block them so that they can't even reach us?
 
This weekend I spent a good couple of hours staring at my live firewall logs. What I saw was constant port scans from IPs all across the world (Bulgaria, America, Netherlands etc.) Not even scanning random ports, just going down the list like 39000, 39001, 39002 etc. I disconnected for a while to force a new IP address but that did not change, just the source IPs changed.

My firewall drops the packet, it doesn't block the packet (there is a difference).

My question is, should we just live with it and trust our CPE? Or should we be asking our ISPs to implement some algorithm to identify port scans and block them so that they can't even reach us?
You secure your own network. The end
 
You secure your own network. The end
Yes that goes without saying, I just wonder, if there is so much port scanning going on accross the whole of the ISP network, they can probably clear that away? My firewall logs will look much better
 
This weekend I spent a good couple of hours staring at my live firewall logs. What I saw was constant port scans from IPs all across the world (Bulgaria, America, Netherlands etc.) Not even scanning random ports, just going down the list like 39000, 39001, 39002 etc. I disconnected for a while to force a new IP address but that did not change, just the source IPs changed.

My firewall drops the packet, it doesn't block the packet (there is a difference).

My question is, should we just live with it and trust our CPE? Or should we be asking our ISPs to implement some algorithm to identify port scans and block them so that they can't even reach us?
We are scanning your porn…
 
What are you using for firewall? I've installed fail2ban on all my servers
 
Welcome to the internet

They are ALL out to get you. Behave appropriately.

DO NOT NAT, unless you have some working knowledge of what it is or what you're doing.
 
It was pretty much stated in the same sentence as if that was your choice of firewall.
No it wasn't. I asked what firewall he used. And then I mentioned I run fail2ban on my servers. Two different, but related points. You can't run fail2ban on your standard Afrihost issue router
 
DO NOT NAT, unless you have some working knowledge of what it is or what you're doing.

Heh? You have to NAT to have internet unless you have only one client device.

Also there’s no real danger in it either.

Think you may be confusing terms and referring to something else.
 
What are you using for firewall? I've installed fail2ban on all my servers
I'm using Opnsense. isn't fail2ban a tool to monitor open ports, and then dropping failed attempts on that port? I don't have any ports open at this stage, so it's more just port scans I am seeing
 
Welcome to the internet

They are ALL out to get you. Behave appropriately.

DO NOT NAT, unless you have some working knowledge of what it is or what you're doing.
I do have NAT, because ..... IPv4, you know. I don't have a static IPv4 connection. But why would that be any different? Every public IP address I get from Afrihost has continuous port scans going on. It's a filthy world out there on internet streets.
 
Heh? You have to NAT to have internet unless you have only one client device.

Also there’s no real danger in it either.

Think you may be confusing terms and referring to something else.
We're discussing the external interface.

Port forwarding is a NAT.

Is this confusing?
 
We're discussing the external interface.

Port forwarding is a NAT.

Is this confusing?
I think you have it wrong. Port forwarding is letting external traffic into/ through your firewall and directing it to a specific internal ip and port. I'd agree with 'don't port forward'. NAT was invented so that many of your network devices could share the same public IP. Your outbound packets gets mapped to your public ip and gets mapped back to the original ip on the way back
 
Port forwarding is letting external traffic into/ through your firewall and directing it to a specific internal
Um. Yes.

It is a form of NAT and NAT, (or Static NAT), is common use when referring to external interfaces.
 
Pretty much the norm, which can be a bit disconcerting if you are watching your logs like a hawk...

I have, however, definitely noticed an uptick in port scans/SYN attempts to certain ports over the last year or so, so I explicitly drop any packets destined for those ports. Port scanners get added to a 30-day blacklist and then dropped at the pre-routing level.

Things are a bit empty at the moment since I did a firmware update on Friday, but most months 10k-15k unique IPs end up in my blacklist...
Screenshot 2026-08-04 094646.png

Screenshot 2026-08-04 094917.png

Screenshot 2026-08-04 094805.png

Screenshot 2026-08-04 095033.png
 
Top
Sign up to the MyBroadband newsletter
X