Welcome Guest ( Log In | Register )

Outline · [ Standard ] · Linear+

 Blocked Ports & Protocols by ISP, List of blocked ports by local ISPs

views
     
TSsoonwai
post Mar 2 2017, 01:17 PM, updated 9y ago


********
All Stars
11,459 posts

Joined: Oct 2007
From: KL


Here's a list of blocked ports and protocols by our local ISPs. Just in case you're wondering why you can't SSH back to your router.

Please report any blocked ports/protocols and I'll update the list. Do some tests first to be sure.

If you're not sure. For example, if you cannot ftp from Maxis to UniFi, port 21 may be blocked by either or both of them. Just mention that and I or someone else can check.

Also let me know if there're any mistakes or changes. Sometimes blocked ports become unblocked temporarily. Like during the last major outage for UniFi, normally blocked ports were no longer blocked probably due to TM's re-routing exercise.

UniFi
Port 22SSHPartial
Port 23TelnetPartial
Port 25SMTP
*Partial: The blocks are not on all subnets. Hmmm, some routers/firewalls not configured.

Maxis Broadband

Maxis Mobile
Protocol 47GRE (e.g.: for PPtP VPN)

TIME

Others

This post has been edited by soonwai: Mar 2 2017, 01:44 PM
vanpersie91
post Mar 2 2017, 01:18 PM

Regular-ly posting shits and stuffs
******
Senior Member
1,478 posts

Joined: Jan 2009
From: Hurr Durr Herp Derp Land
why some ports might be blocked?
TSsoonwai
post Mar 2 2017, 01:37 PM


********
All Stars
11,459 posts

Joined: Oct 2007
From: KL


QUOTE(vanpersie91 @ Mar 2 2017, 01:18 PM)
why some ports might be blocked?
*
Probably to prevent "hackers" from trying to brute force routers or servers. If you check the log, you'd be surprised at how many attempts are made on your own router everyday.

Here's an example from one of my routers taken just a few mins ago.
user posted image

This post has been edited by soonwai: Mar 2 2017, 01:38 PM
vanpersie91
post Mar 2 2017, 01:49 PM

Regular-ly posting shits and stuffs
******
Senior Member
1,478 posts

Joined: Jan 2009
From: Hurr Durr Herp Derp Land
QUOTE(soonwai @ Mar 2 2017, 01:37 PM)
Probably to prevent "hackers" from trying to brute force routers or servers. If you check the log, you'd be surprised at how many attempts are made on your own router everyday.

Here's an example from one of my routers taken just a few mins ago.
user posted image
*
wow. just few minutes already almost 30 records

whole day might reach hundreds or thousands sweat.gif
TSsoonwai
post Mar 2 2017, 02:06 PM


********
All Stars
11,459 posts

Joined: Oct 2007
From: KL


QUOTE(soonwai @ Mar 2 2017, 01:37 PM)
Probably to prevent "hackers" from trying to brute force routers or servers. If you check the log, you'd be surprised at how many attempts are made on your own router everyday.

Here's an example from one of my routers taken just a few mins ago.
user posted image
*
Yeah, I know, scary right? And most routers have default username like admin so the bad guys only have to guess the password. i.e.: single factor authentication (1FA)
That's why I tell my friends, if your router allows it, change the username also. Instantly you have 2FA authentication.
edward88
post Mar 2 2017, 09:42 PM

Casual
***
Junior Member
351 posts

Joined: Jul 2007


QUOTE(vanpersie91 @ Mar 2 2017, 01:49 PM)
wow. just few minutes already almost 30 records

whole day might reach hundreds or thousands sweat.gif
*
you can disable the service or add access list to prevent this.
nexona88
post Mar 2 2017, 11:47 PM

The Royal Club Member
*********
All Stars
48,588 posts

Joined: Sep 2014
From: REality
QUOTE(soonwai @ Mar 2 2017, 01:37 PM)
Probably to prevent "hackers" from trying to brute force routers or servers. If you check the log, you'd be surprised at how many attempts are made on your own router everyday.

Here's an example from one of my routers taken just a few mins ago.
user posted image
*
Wah so much shocking.gif
TSsoonwai
post Mar 3 2017, 12:07 AM


********
All Stars
11,459 posts

Joined: Oct 2007
From: KL


QUOTE(nexona88 @ Mar 2 2017, 11:47 PM)
Wah so much shocking.gif
*
DNS Amplification attack even worse. You don't see anything in your logs. Just lots of outgoing traffic from your router to the target.
See here: https://forum.lowyat.net/topic/3860279

Anime4000
post Jul 24 2019, 10:32 PM

Look at all my stars!!
*******
Senior Member
2,400 posts

Joined: Jul 2009
From: /dev/null


TM: Unifi, Streamyx port 6667 tcp/udp is block, many online game use this port, eg: EA games
MonkeYsua
post Nov 20 2021, 05:57 PM

Casual
***
Junior Member
402 posts

Joined: Jan 2003
From: KL, Kepong


UNIFI blocked 445 and 4444, do update ya
Anime4000
post Nov 21 2021, 08:34 PM

Look at all my stars!!
*******
Senior Member
2,400 posts

Joined: Jul 2009
From: /dev/null


QUOTE(MonkeYsua @ Nov 20 2021, 05:57 PM)
UNIFI blocked 445 and 4444, do update ya
*
that sucks, This very reasons I use Maxis Fiber
Moogle Stiltzkin
post Mar 10 2023, 09:49 AM

Look at all my stars!!
*******
Senior Member
4,476 posts

Joined: Jan 2003
does tmnut block 443?
asellus
post Mar 10 2023, 10:29 AM

#gompusas
Group Icon
Elite
4,541 posts

Joined: Jan 2003
From: BSRPPG51 Access Concentrator


QUOTE(Moogle Stiltzkin @ Mar 10 2023, 09:49 AM)
does tmnut block 443?
*
No.
Moogle Stiltzkin
post Mar 10 2023, 02:38 PM

Look at all my stars!!
*******
Senior Member
4,476 posts

Joined: Jan 2003
QUOTE(asellus @ Mar 10 2023, 10:29 AM)
No.
*
thx.

then i'm confused then. i was trying to get netgear insight cloud to work, so i thought ok, i have to port forward 443. but that didn't work, so this is why i thought maybe the isp blocked.

but since it's not now i'm out of ideas hmm.gif
https://kb.netgear.com/000062467/Which-doma...Managed-devices


How to Set Up Port Forwarding in pfSense Software
https://www.youtube.com/watch?v=iFAuK_m7JxE



This post has been edited by Moogle Stiltzkin: Mar 10 2023, 02:42 PM
papyrous
post Mar 10 2023, 03:12 PM

Getting Started
**
Junior Member
214 posts

Joined: May 2017
QUOTE(Moogle Stiltzkin @ Mar 10 2023, 02:38 PM)
thx.

then i'm confused then. i was trying to get netgear insight cloud to work, so i thought ok, i have to port forward 443. but that didn't work, so this is why i thought maybe the isp blocked.

but since it's not now i'm out of ideas  hmm.gif
https://kb.netgear.com/000062467/Which-doma...Managed-devices
How to Set Up Port Forwarding in pfSense Software
https://www.youtube.com/watch?v=iFAuK_m7JxE
*
these should be outbound, are they blocked at your DNS level by Pfblocker?
failed.hashcheck
post Mar 10 2023, 03:30 PM

Neighborhood plant pathologist
*******
Senior Member
2,096 posts

Joined: Aug 2009
From: Shithole Klang
Celcom, test with netcat to/from GCP instance in SG.

CODE
for i in 20 21 22 23 25 69 53 88 110 119 123 143 161 465 587 636 989 990 995 1194 4444 6667 80 8080 443 ; do nc -lvnp $i & done


user posted image

Only port 25 blocked.
dev/numb
post Mar 14 2023, 03:41 PM

On my way
****
Junior Member
691 posts

Joined: Nov 2021
QUOTE(Anime4000 @ Jul 24 2019, 10:32 PM)
TM: Unifi, Streamyx port 6667 tcp/udp is block, many online game use this port, eg: EA games
*
I don’t think TM intentionally wants to block the games. TCP 6667 is the old default IRC port. Probably it’s a holdover from the old days when everyone was pirating via IRC.
Moogle Stiltzkin
post Mar 15 2023, 04:03 AM

Look at all my stars!!
*******
Senior Member
4,476 posts

Joined: Jan 2003
QUOTE(papyrous @ Mar 10 2023, 03:12 PM)
these should be outbound, are they blocked at your DNS level by Pfblocker?
*
could be confused.gif
https://community.netgear.com/t5/NETGEAR-In...ce/td-p/1683183


but i did however spin up asus router and factory reset (no pfblocker, no complicated settings/setup). only setting i did was isp and enable upnp. still didn't work.

could it be because of this? hmm.gif
https://www.malaysiatrend.com/2021/10/15/tm...-it-impacts-you

https://forum.lowyat.net/topic/5205674/+400

This post has been edited by Moogle Stiltzkin: Mar 15 2023, 04:05 AM

 

Change to:
| Lo-Fi Version
0.0190sec    0.83    5 queries    GZIP Disabled
Time is now: 23rd December 2025 - 04:19 AM