how to "stealth" a Zyxel NBG-417N
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Plusnet Community
- :
- Forum
- :
- Help with my Plusnet services
- :
- Full Fibre
- :
- how to "stealth" a Zyxel NBG-417N
how to "stealth" a Zyxel NBG-417N
30-12-2010 10:40 PM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
Plusnet has very kindly let me have one of these to try, and it seems to be working fine, but according to Shields Up, the network is still visible. How can I put it in "stealth" mode? Any ideas?
John
Re: how to "stealth" a Zyxel NBG-417N
30-12-2010 10:45 PM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
Re: how to "stealth" a Zyxel NBG-417N
30-12-2010 10:58 PM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
Under Security >Firewall > Services select "do not respond to requests for unauthorised services" and also set "Respond to PING on" to "LAN"
Re: how to "stealth" a Zyxel NBG-417N
31-12-2010 1:02 AM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
Quote Note that the probing packets must first traverse the NBG-417N's firewall mechanism before reaching this anti-probing mechanism.
Therefore if the firewall mechanism blocks a probing packet, the NBG- 417N reacts based on the firewall policy, which by default, is to send a
TCP reset packet for a blocked TCP packet. You can use the command "sys firewall tcprst rst [on|off]" to change this policy. When the firewall
mechanism blocks
But I'm afraid in my ignorance, it doesn't help much.
John
Re: how to "stealth" a Zyxel NBG-417N
31-12-2010 1:09 AM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
Re: how to "stealth" a Zyxel NBG-417N
31-12-2010 1:32 AM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
According to the bit I quoted from the manual, it appears that the default is to send a response, if the probe is stopped at the firewall. It gives the command to prevent it, but I don't know how to set that command.
John
Re: how to "stealth" a Zyxel NBG-417N
31-12-2010 2:02 AM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
If its not working you need to contact Zyxel and query what the problem is.
Re: how to "stealth" a Zyxel NBG-417N
31-12-2010 10:13 AM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
Quote Note that the probing packets must first traverse the NBG-417N's firewall mechanism before reaching this anti-probing mechanism.
Therefore if the firewall mechanism blocks a probing packet, the NBG- 417N reacts based on the firewall policy, which by default, is to send a
TCP reset packet for a blocked TCP packet. You can use the command "sys firewall tcprst rst [on|off]" to change this policy. When the firewall
mechanism blocks
Have you tried TELNET to issue this command?
Re: how to "stealth" a Zyxel NBG-417N
31-12-2010 10:40 AM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
@ knowdice - I guessed that's what I needed to do, but how do I do that? I can run telnet of course, but how do I access the router and give it the command?
John
Re: how to "stealth" a Zyxel NBG-417N
31-12-2010 11:05 AM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
Re: how to "stealth" a Zyxel NBG-417N
31-12-2010 11:43 AM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
Most if not all Zyxel routers I have tried in the past have allowed telnet, you just get prompted for the password then enter the command at the prompt.
Re: how to "stealth" a Zyxel NBG-417N
31-12-2010 1:18 PM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator

John
Re: how to "stealth" a Zyxel NBG-417N
01-01-2011 1:26 PM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
Quote Thanks for contacting. You can block ICMP traffic using the firewall, but for any advanced security features you will need to upgrade to our professional security devices.
So being able to stealth ports is a "professional" security issue

John
Re: how to "stealth" a Zyxel NBG-417N
01-01-2011 2:28 PM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
Not responding on closed ports is quite frankly the norm today, there is nothing professional about it and being asked to pay extra for this would lead me straight to another supplier.
Re: how to "stealth" a Zyxel NBG-417N
01-01-2011 3:25 PM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator

John
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Plusnet Community
- :
- Forum
- :
- Help with my Plusnet services
- :
- Full Fibre
- :
- how to "stealth" a Zyxel NBG-417N