Zoom X6 Modem/Router Security Issues

DoZZa

Distinguished
Dec 29, 2007
37
0
18,530
Hi all,

I have just setup my new Zoom X6 Router.

Its a good router and has added an extra 1.5kbps to my connection speed right out of the box.

However I am not happy with the security of the X6.

1. It responds to pings. I cant see an option anywhere which allows me to block or unblock ping (ICMP).

2. If I do a port scan via Shields Up or other port scanning websites port 80 is shown as CLOSED. Where all other ports are STEALTH.

I called Zoom tech support and they where next to useless. Sending me an email telling me how to configure a DMZ server. Not sure why they did this as I cant see how allowing a DMZ with the IP of 10.0.0.252 would stealth port 80, but thats what it said in the email. I tried it out of pure curiosity knowing it wasn't going to work and sure enough it didn't.

I am running ESET Smart Security and all firewall settings there are fine.

Does anyone have any experience with the X6 and its quirky security configuration?

Another thing is this. If I disable NAT, I am then not able to access and websites at all. My old router, all though NAT equipped, never had NAT enabled and that would connect to all websites without NAT being enabled. No port forwarding was needed etc.

I have the latest firmware version of 5.0.2-70 installed.

Any help is gratefully received.

Thanks

DoZZa
 

ti994a

Distinguished
Mar 28, 2008
1
0
18,510
Hi DoZZa, I had the same problem. Did you get it resolved? If so I'm sure you know by now it is a firewall rule that needs to be added for pings to be blocked. I have found no way to stealth port 80 on this box. The only option I had was changing the port number.
 

yogbod53

Distinguished
Jun 16, 2010
1
0
18,510
I know this is old, but it comes up first in the results on Google. I have had the same problem, but finally managed to get it fixed. The instructions are quite long so I stuck them on my blog

http://trappedinmagazines.wordpress.com/2010/06/16/zoom-x6-firewall/

Zoom and Conexant don't seem to have given manuals for the CLI, but there was a Billion router manual that did, and that helped me. I've included the links in the blog post too.

Hope it helps.

Iain
 

seacliff

Distinguished
Jun 14, 2010
65
0
18,640



Is there a reason why you want to disable NAT? I can't see any security issue about this.. maybe you could light me out on this one?

The way I see NAT is a way to forward specific packet from WAN to the right LAN PC. Since you have 1 WAN IP address and multiple LAN IP address (I suppose), it maps each LAN IP with an unique port number when sending a packet through WAN. If you disable that, your router won't know who send something and won't be able to know where to send it back. This was implemented to get rid of the issue where you had to map 1 local to 1 WAN IP address to communicate through a router.

I can't either figure out why your other router was ok without NAT or any sort of forwarding.