Kitz ADSL Broadband Information
adsl spacer  
Support this site
Home Broadband ISPs Tech Routers Wiki Forum
 
     
   Compare ISP   Rate your ISP
   Glossary   Glossary
 
Please login or register.

Login with username, password and session length
Advanced search  

News:

Author Topic: How to block MQTT ports  (Read 17606 times)

broadstairs

  • Kitizen
  • ****
  • Posts: 3736
How to block MQTT ports
« on: October 27, 2025, 01:51:46 PM »

Hope this is the righg place! I have discovered that several devices I have are using MQTT to call home. I want to prevent this is there any easy way to do this?

Stuart
Logged
ISP:Vodafone Router:Vodafone Wi-Fi hub FTTP

tubaman

  • Senior Kitizen
  • ******
  • Posts: 13013
Re: How to block MQTT ports
« Reply #1 on: October 28, 2025, 08:28:21 AM »

A quick search suggests the standard ports used by MQTT are 1883 for unencrypted comms and 8883 for encrypted comms, but if you block those ports entirely you may find that some devices stop working correctly.
Logged
BT FTTC 55/10 Huawei Cab - Zyxel VMG1312-B10A > BT 'Smart' Hub 2

broadstairs

  • Kitizen
  • ****
  • Posts: 3736
Re: How to block MQTT ports
« Reply #2 on: October 28, 2025, 10:01:46 AM »

A quick search suggests the standard ports used by MQTT are 1883 for unencrypted comms and 8883 for encrypted comms, but if you block those ports entirely you may find that some devices stop working correctly.

Yes I found that and neither of those were active but my suspicion is that they are only opened to communicate and then closed again. I have a Vodafone router which only allows UPNP to be turned off no individual ports and I need this for my digital home phone. I also found MQTT can use port 443 (I think that's the number). I checked all those ports with Shields Up and they were stealth!

Stuart
Logged
ISP:Vodafone Router:Vodafone Wi-Fi hub FTTP

tubaman

  • Senior Kitizen
  • ******
  • Posts: 13013
Re: How to block MQTT ports
« Reply #3 on: October 28, 2025, 03:10:33 PM »

Port 443 is usually for HTTPS but I suppose they could be using it for a different purpose. Shields Up checks that the ports can't be seen with a probe from outside but as you say it's likely they are opened and then closed again. What is your actual concern here as a lot of IOT devices call home on a regular basis?
Logged
BT FTTC 55/10 Huawei Cab - Zyxel VMG1312-B10A > BT 'Smart' Hub 2

Alex Atkin UK

  • Addicted Kitizen
  • *****
  • Posts: 5587
    • Thinkbroadband Quality Monitors
Re: How to block MQTT ports
« Reply #4 on: October 30, 2025, 07:19:06 PM »

Are they even opened at all?  More likely they are connecting from the inside out, no port opening required.
Logged
Broadband: Zen Full Fibre 900 + Three 5G Routers: pfSense (Intel N100) + GL.iNet GL-X3000
Network: Netgear MS510TXUP, Netgear MS510TXPP, Netgear GS110EMX WiFi: Zyxel NWA210AX + Ubiquity NanoHD
Broadband History & Ping Monitor