端口转发与端口状态疑问:为何转发端口26显示为filtered而非closed?
Great question—let’s break this down based on how your Thomson TWG870 router handles unsolicited external traffic, and how port scanners interpret different responses.
Key Background: Port Scanner States
First, a quick recap of what those states mean to a scanner:
- Open: The scanner sends a request, and gets a valid response from a service (like your SSH server on 22).
- Closed: The scanner sends a request, and the target (either the router or your internal host) sends back an RST (reset) packet, indicating no service is listening on that port.
- Filtered: The scanner sends a request, but gets no response at all. This means the packet was either dropped by a firewall/router, or never reached the target.
Why Port 26 is Filtered
Your Thomson TWG870 has a default behavior for ports you haven’t configured port forwarding for: it drops incoming packets instead of forwarding them or sending an RST response.
Here’s the play-by-play:
- When you scan port 22: The router sees the port forwarding rule, sends the packet to 192.168.0.10:22. Your SSH server responds, so the scanner marks it as open.
- When you scan port 26: There’s no port forwarding rule, so the router doesn’t send the packet to your internal host. Instead, it just discards the incoming request entirely. Since the scanner gets no response, it can’t tell if the port is closed (no service) or blocked by a filter—so it labels it as filtered.
How to Verify This
If you want to confirm this is the router’s behavior, try adding a port forwarding rule for port 26 pointing to 192.168.0.10:26 (even though nothing’s listening there). Now when you scan port 26:
- The router forwards the packet to your internal host.
- Your host sees the request to port 26 (no service listening), so it sends back an RST packet.
- The scanner will now mark port 26 as closed, because it got a clear "no service here" response.
This is a common behavior in many consumer routers—they prioritize security by not revealing which internal ports are open/closed to external scanners, instead dropping unforwarded traffic to avoid giving away network details.
内容的提问来源于stack exchange,提问作者Ringger81

