Need to get in touch with a Sales Representative? Talk to a Business Expert HERE .
sabnick's profile

Tutor

 • 

4 Messages

Friday, August 5th, 2016 8:40 PM

Failing PCI Compliance with Security Metrics due to port 61001 being open on 5031NV gateway

Hoping for some help with this....we have 4 retail stores with U-Verse that are failing PCI Compliance scans via Security Metrics because port 61001 is open and responding on the 5031NV gateways. We need to seal that hole up otherwise U-Verse is not going to be a viable internet solution for our company.

 

I've found a lot of information about this issue from other posts and other websites, but have found no "fix". The best proposed solution that I've found, which is putting a firewall behind the 5031NV gateway and using DMZplus mode, has not worked. Despite setting a firewall rule to deny all traffic to destination 61001, I can use Sysinternals' PsPing and get replies all day using the WAN IP:61001 which means the modem is still taking that port traffic and not passing it on as I've instructed it to do so via DMZplus mode.

 

Are there any other ways to fix this and shut the port down?

I've also tried setting a port forward ("pin hole") in the gateway to forward 61001 to the firewall rather than using DMZplus mode, but the same still occurs - traffic is acknowledged by the modem itself. I need the modem to stop doing that.

 

Please advise.

Thanks!

Community Support

 • 

3.1K Messages

8 years ago

Hello @sabnick

 

Thank you for your recent posting. We appreciate your participation within the Business Community. I will be more than happy to assist you! In order for me to research your issue, I will need to verify some information. Please send me a private message by clicking here: https://forums.att.com/t5/notes/privatenotespage/tab/compose/note-to-user-id/3512576

 

And include the following details:                                                               

Full Name and Name on Business Account:

Wireless # (if applicable):

Preferred Contact #:

Preferred time to be contacted (including time zone)

Email address:

 

Thank you,

Angela

Tutor

 • 

4 Messages

8 years ago

Account information and contact info has been sent as requested, thank you.

Contributor

 • 

2 Messages

8 years ago

@sabnick did you get this issue resolved?  I'm having the exact same problem.

thanks,

texans_99

Tutor

 • 

4 Messages

8 years ago

texans_99, no, it has not been resolved. I received 2 phone calls, 1 passed me on to another, and now the latter has passed me back on to the former. However, before doing so, he stated that U-Verse Technical Support has informed him that all ports are closed on the Gateways, which is incorrect.

 

I'm surprised I need to provide proof of this, as I'd believe that anyone with Tier 1 level networking experience would know how to do this themselves (testing WAN address, port 61001) and realize that statement is incorrect, but I digress:

http://imgur.com/W1jYluZ

http://imgur.com/Nm5pLRT

 

Port 61001 is not closed. If it were closed, it would not respond, as WAN address, port 21 testing here clearly demonstrates:

http://imgur.com/KKzFPhb

http://imgur.com/Z2l6hge

 

Call #2 told me if I have any issues to call caller #1 and they (for a fee) can help me out, IE they are tech support on demand. I don't need tech support on demand, because I don't have a tech support on demand issue - I have an AT&T Technical Support based Service issue, because the Gateway has an open port 61001.

 

I'm beginning to think that this is one of those things where the reason those other posts I've found with no actual answer or closure are because those people got the same runaround, and the alternative here is to cancel AT&T Service and go with a different provider.

 

I have 4 stores failing Security Metrics PCI scanning all for port 61001 (and in one case, also port 51001), 3 of the 4 are using 5031NV Gateways and the 4th has a 3800HGV-B gateway. Same issue across the board...so unfortunately this isn't a "specific gateway" issue where I can call and get a gateway swapped out for a different version that does not have open ports.

Tutor

 • 

4 Messages

8 years ago

Update to this -

After getting repeated runaround with AT&T techs on the phone, we phoned and asked to get a replacement modem to get rid of the 2+ years old 3800HGV-B gateway. We were told that we'd have to pay $149 for a technician to go out to the store. We approved the charge, but then were told that there's no guarantee the tech will replace the modem anyway. Tech was then non-helpful.

 

We asked for a supervisor and were told prior to patching through that the supervisor would give the same answer.

 

Oh but it gets better....not only did the supervisor give the same answer, he also stated point blank unequivocally that "no AT&T modems pass PCI Compliance".

 

Let this be a warning to anyone with AT&T or thinking of getting AT&T: if you need to have a PCI Compliant environment due to Point Of Sale systems or cardholder data, you can scratch AT&T off your list as a possible ISP.

 

We are in the process of switching our stores off of AT&T and over to a different provider. Our company spends six figures in service from AT&T on an annual basis, and we got some of the worst customer service (even by a SUPERVISOR) that I've ever seen or heard.

Contributor

 • 

2 Messages

7 years ago

What service are you switching to?  We are having the same issues and are getting no help from anyone.  We have an option with our credit card service in which we can pay $20 a month and not have to be compliant, but with all the non help that makes me nervous as I am not sure they will stand behind us if there is a breech.  We are a very small company and this is not something we have the technical help to understand nor do we know anyone that can help us.

 

dee

Community Support

 • 

3.1K Messages

7 years ago

Hello @Beacon

 

Thank you for reaching out on our Business Community. Sorry to hear about the issues with your account. I will be glad to help. Please provide us with some more details for your concerns by sending us a private message by click here https://forums.att.com/t5/notes/privatenotespage/tab/compose/note-to-user-id/3512576

 

Please include the following information.

 

Full Name:

Preferred Contact #:

Preferred Time to be contacted (include time zone):

Email Address:

Account #:

 

Thank you,

Lisa AT&T Social Media Manager

 

Not finding what you're looking for?