We have seen DDOS attacks using port 1900 which max out the customers upload. This isn't terrible for our network, but the customers connection doesn't work very well.
We generally don't block ports, but I made an exception for 1900 and 5351. We block UDP traffic inbound to these ports. The chances of DDOS/abuse is too high, and it is documented as a port used for UPnP and NAT-PMP which is not supposed to be public. The chances of any other service using these is pretty low. We've not had any complaints. On 5/18/2015 9:18 AM, Ken Hohhof wrote: > I finally started getting ShadowServer reports which are nice. > > One thing I notice is that about 5% of customers still have routers with > SSDP (the discovery protocol for UPnP) exposed on the WAN side. This > despite the fact that I scanned the network earlier this year and sent > notices to every single customer with this vulnerability. It tells me > very few did anything about it. Most of these are DLink DIR-615 > routers, and except for the very last version of that router, there is > no FW update, their only solution is to disable UPnP in the menus. > Apparently that's too difficult for customers. > > My question: is this serious enough to worry about? Should I just wait > for those DLink routers (or their owners) to die? > > I guess another solution would be to block ports 1900/2049/5783 but > these might be legitimately in use as ephemeral ports and I don't like > blocking high numbered ports. >
