HOWTO: Block Intel AMT ports in the firewall?

Report wireless and/or network connectivity problems in this forum.

Moderator: Moderators

Post Reply
NavigatorN
Posts: 4
Joined: Sat May 27, 2017 7:49 am

HOWTO: Block Intel AMT ports in the firewall?

Post by NavigatorN »

Hi all,

I am new around here and just flashed my beloved TP1043nd-V1 from OpenWRT to Gargoyle 1.9.2. That worked fine. OpenWRT is too difficult for me since i am not an network admin.

The point is i want to block ports 5900, 16992-16995, 623 and 664 as they are all related to the recent Intel AMT open backdoor publication.

But under the firewall section i cannot see an option to block these ports and drop the package, i prefer drop and not reject.

Anyone a noob guideline?

tapper
Moderator
Posts: 1076
Joined: Sun Oct 13, 2013 5:49 pm
Location: Stoke-on-trent UK

Re: HOWTO: Block Intel AMT ports in the firewall?

Post by tapper »

Look under firewall set the ports to reject.. Then install winscp log in to your router and find the /etc/config/firewall file. In the file look for the rules for the ports you blocked and change the line were it says reject to drop. When using winscp your username will be root and password is the one you use to log in to the user interface.
Linksys WRT3200ACM
NETGEAR Nighthawk R7800
NETGEAR R6260

NavigatorN
Posts: 4
Joined: Sat May 27, 2017 7:49 am

Re: HOWTO: Block Intel AMT ports in the firewall?

Post by NavigatorN »

Under firewall>restrictions do i have to block Remote or local ports?

And do i have to create a rule for each port or can i add multiple. And if so how to separate the port numbers?

Lantis
Moderator
Posts: 7063
Joined: Mon Jan 05, 2015 5:33 am
Location: Australia

Re: HOWTO: Block Intel AMT ports in the firewall?

Post by Lantis »

I believe they will be local ports.
I also didn't find mention of port 5900?

List them like
623,644,16992-16995
https://lantisproject.com/downloads/gargoylebuilds for the latest releases
Please be respectful when posting. I do this in my free time on a volunteer basis.

NavigatorN
Posts: 4
Joined: Sat May 27, 2017 7:49 am

Re: HOWTO: Block Intel AMT ports in the firewall?

Post by NavigatorN »

I can do a port scan from various websites and all the ports are closed from the internet.
But how to test them from my local machine? AMT is yelling out as I read it...

Post Reply