Page 1 of 1

HOWTO: Block Intel AMT ports in the firewall?

Posted: Sat May 27, 2017 8:00 am
by NavigatorN
Hi all,

I am new around here and just flashed my beloved TP1043nd-V1 from OpenWRT to Gargoyle 1.9.2. That worked fine. OpenWRT is too difficult for me since i am not an network admin.

The point is i want to block ports 5900, 16992-16995, 623 and 664 as they are all related to the recent Intel AMT open backdoor publication.

But under the firewall section i cannot see an option to block these ports and drop the package, i prefer drop and not reject.

Anyone a noob guideline?

Re: HOWTO: Block Intel AMT ports in the firewall?

Posted: Sat May 27, 2017 6:05 pm
by tapper
Look under firewall set the ports to reject.. Then install winscp log in to your router and find the /etc/config/firewall file. In the file look for the rules for the ports you blocked and change the line were it says reject to drop. When using winscp your username will be root and password is the one you use to log in to the user interface.

Re: HOWTO: Block Intel AMT ports in the firewall?

Posted: Sun Jun 11, 2017 11:47 am
by NavigatorN
Under firewall>restrictions do i have to block Remote or local ports?

And do i have to create a rule for each port or can i add multiple. And if so how to separate the port numbers?

Re: HOWTO: Block Intel AMT ports in the firewall?

Posted: Sun Jun 11, 2017 6:19 pm
by Lantis
I believe they will be local ports.
I also didn't find mention of port 5900?

List them like
623,644,16992-16995

Re: HOWTO: Block Intel AMT ports in the firewall?

Posted: Mon Jun 12, 2017 9:49 am
by NavigatorN
I can do a port scan from various websites and all the ports are closed from the internet.
But how to test them from my local machine? AMT is yelling out as I read it...