Unexpected and Uncofingured Port Forwarding from Netgear Switch/Router
May 20, 2006 1:09 PM
Subscribe
On my XP system, the recently installed Norton anti-worm app told me that my Netgear RP614v2 NAT-enabled router attempted to udp connect to my port number 2061 from its port 12024. However, there is no port fowarding or triggering enabled, nor is there a DMZ address configured at all.
There is some port forwarding configured via UPnP...but not that one or to this IP. UPnP config in the Netgear does say one address/port is mapped to a different IP and it was configured by the Azureus bittorrent client via its UPnP plug-in. But, again, this is only one port and to a different IP than my XP machine (whose IP is static via DHPP). SPI is on, ping reply is off.
Also, remote configuration is not enabled on the Netgear. The router firmware is 29 2004.
How could this happen? Any ideas?
I know that UPnP is supposedly insecure, but I confess I've never researched the matter nor worried about it very much. Immediately after this incident, I've turned off UPnP in the Netgear config and switched the XP machine running Azureus to use a fixed IP address and configured port forwarding for that one port and IP.
posted by Ethereal Bligh to computers & internet (8 comments total)
UDP 2061 is the NetMount port. If a machine on your network attempted a NetMount call through the router, you'd see UDP 2061 from the router.
posted by eriko at 1:25 PM on May 20, 2006