# How to prevent devices from announcing themselves to stdiscosrv with random ports in addition to port 22000, while nat and lan discovery are already disabled?

**URL:** https://forum.syncthing.net/t/how-to-prevent-devices-from-announcing-themselves-to-stdiscosrv-with-random-ports-in-addition-to-port-22000-while-nat-and-lan-discovery-are-already-disabled/22814
**Category:** Support
**Created:** [September 18, 2024, 11:11am UTC](https://forum.syncthing.net/t/how-to-prevent-devices-from-announcing-themselves-to-stdiscosrv-with-random-ports-in-addition-to-port-22000-while-nat-and-lan-discovery-are-already-disabled/22814 "2024-09-18T11:11:20Z")
**Posts on this page:** 20
**Page:** 1

<div class="post-metadata">

### Author: ![firesnake](https://forum.syncthing.net/letter_avatar_proxy/v4/letter/f/dbc845/32.png) [@firesnake](https://forum.syncthing.net/u/firesnake)
#### Post date: [September 18, 2024, 11:11am UTC](https://forum.syncthing.net/t/how-to-prevent-devices-from-announcing-themselves-to-stdiscosrv-with-random-ports-in-addition-to-port-22000-while-nat-and-lan-discovery-are-already-disabled/22814/1 "2024-09-18T11:11:20Z")

</div>

```plaintext
$ curl -X GET --insecure "https://rsync:8443/?device=N74QTL7-GVVDDQK-OPTDSXQ-DEGHCK7-ZB7VPOS-ZIKWZJ5-5WKHG3L-2SGOVAK"
{"seen":"2024-09-18T13:59:29.367939221+03:00","addresses":["tcp4://10.x.x.x:22000","tcp4://10.x.x.x:42676","tcp4://10.x.x.x:42680","tcp4://10.x.x.x:42684","tcp4://10.x.x.x:42688","tcp4://10.x.x.x:42694","tcp4://10.x.x.x:42700","tcp4://10.x.x.x:42706","tcp4://10.x.x.x:42714","tcp4://10.x.x.x:42720","tcp4://10.x.x.x:42722","tcp4://10.x.x.x:42732","tcp4://10.x.x.x:42738","tcp4://10.x.x.x:42744","tcp4://10.x.x.x:42750","tcp4://10.x.x.x:42756","tcp4://10.x.x.x:42762","tcp4://10.x.x.x:42768","tcp4://10.x.x.x:42774","tcp4://10.x.x.x:42786","tcp4://10.x.x.x:42792","tcp4://10.x.x.x:42802"]}

```

`announceLANAddresses` is false

`natEnabled` is false

the app does not bind to announced ports but lookups from discovery server is causing unnecesary traffic by failed connection attempts[\*]

the only open ports are the web gui and 22000/tcp

[\*] `[ONX5K] 2024/09/18 14:09:31.346886 service.go:1172: DEBUG: dialing N74QTL7-GVVDDQK-OPTDSXQ-DEGHCK7-ZB7VPOS-ZIKWZJ5-5WKHG3L-2SGOVAK tcp4://10.x.x.x:42680 error: dial tcp4 10.x.x.x:42680: connect: connection refused`

```plaintext
$ diff --suppress-common-lines -y .local/state/syncthing/config.xml config.xml-default | grep -E -v 'user|password|apikey'
    <folder id="default" label="Default Folder" path="/home/s | <folder id="default" label="Default Folder" path="/home/s
        <device id="ONX5KQ3-ST4PELN-EOLR4GG-KUDGPX3-2NCAABW-H <
            <encryptionPassword></encryptionPassword> <
        </device> <
        <maxConflicts>0</maxConflicts> | <maxConflicts>10</maxConflicts>
        <blockPullOrder>random</blockPullOrder> | <blockPullOrder>standard</blockPullOrder>
    <device id="ONX5KQ3-ST4PELN-EOLR4GG-KUDGPX3-2NCAABW-HZQKY <
        <address>dynamic</address> <
        <paused>false</paused> <
        <autoAcceptFolders>true</autoAcceptFolders> <
        <maxSendKbps>0</maxSendKbps> <
        <maxRecvKbps>3</maxRecvKbps> <
        <maxRequestKiB>0</maxRequestKiB> <
        <untrusted>false</untrusted> <
        <remoteGUIPort>0</remoteGUIPort> <
        <numConnections>0</numConnections> <
    </device> <
    <device id="SXUMNJK-GUG632P-RONH6WD-WI6C6GT-QSEL5VZ-CEYHY <
        <address>dynamic</address> <
        <paused>true</paused> <
        <autoAcceptFolders>false</autoAcceptFolders> <
        <maxSendKbps>0</maxSendKbps> <
        <maxRecvKbps>0</maxRecvKbps> <
        <maxRequestKiB>0</maxRequestKiB> <
        <untrusted>true</untrusted> <
        <remoteGUIPort>0</remoteGUIPort> <
        <numConnections>0</numConnections> <
    </device> <
    <device id="36J46B5-NVJFLWX-N3A3JAE-ZBFM5V6-XKBINMT-JX6KZ <
        <address>dynamic</address> <
        <paused>true</paused> <
        <autoAcceptFolders>false</autoAcceptFolders> <
        <maxSendKbps>0</maxSendKbps> <
        <maxRecvKbps>0</maxRecvKbps> <
        <maxRequestKiB>0</maxRequestKiB> <
        <untrusted>true</untrusted> <
        <remoteGUIPort>0</remoteGUIPort> <
        <numConnections>0</numConnections> <
    </device> <
        <address>0.0.0.0:8384</address> | <address>127.0.0.1:8384</address>
        <listenAddress>tcp4://:22000</listenAddress> | <listenAddress>default</listenAddress>
        <globalAnnounceServer>https://rsync:8443/v2/?id=QKNYI | <globalAnnounceServer>default</globalAnnounceServer>
        <localAnnounceEnabled>false</localAnnounceEnabled> | <localAnnounceEnabled>true</localAnnounceEnabled>
        <maxRecvKbps>3</maxRecvKbps> | <maxRecvKbps>0</maxRecvKbps>
        <startBrowser>false</startBrowser> | <startBrowser>true</startBrowser>
        <natEnabled>false</natEnabled> | <natEnabled>true</natEnabled>
        <urAccepted>-1</urAccepted> | <urAccepted>0</urAccepted>
        <urURL>https://localhost</urURL> | <urURL>https://data.syncthing.net/newdata</urURL>
        <autoUpgradeIntervalH>0</autoUpgradeIntervalH> | <autoUpgradeIntervalH>12</autoUpgradeIntervalH>
        <keepTemporariesH>48</keepTemporariesH> | <keepTemporariesH>24</keepTemporariesH>
        <releasesURL>https://localhost</releasesURL> | <releasesURL>https://upgrades.syncthing.net/meta.json
                                                              > <unackedNotificationID>authenticationUserAndPassword<
        <crashReportingURL>https://localhost</crashReportingU | <crashReportingURL>https://crash.syncthing.net/newcra
        <crashReportingEnabled>false</crashReportingEnabled> | <crashReportingEnabled>true</crashReportingEnabled>
        <stunServer>rsync:3478</stunServer> | <stunServer>default</stunServer>
        <announceLANAddresses>false</announceLANAddresses> | <announceLANAddresses>true</announceLANAddresses>
        <connectionPriorityTcpLan>20</connectionPriorityTcpLa | <connectionPriorityTcpLan>10</connectionPriorityTcpLa
        <connectionPriorityQuicLan>10</connectionPriorityQuic | <connectionPriorityQuicLan>20</connectionPriorityQuic
        <connectionPriorityTcpWan>40</connectionPriorityTcpWa | <connectionPriorityTcpWan>30</connectionPriorityTcpWa
        <connectionPriorityQuicWan>30</connectionPriorityQuic | <connectionPriorityQuicWan>40</connectionPriorityQuic
            <paused>true</paused> | <paused>false</paused>
            <untrusted>true</untrusted> | <untrusted>false</untrusted>

```

---

<div class="post-metadata">

### Author: ![Nummer378](https://forum.syncthing.net/user_avatar/forum.syncthing.net/nummer378/32/5958_2.png) [@Nummer378](https://forum.syncthing.net/u/Nummer378)
#### Post date: [September 18, 2024, 12:30pm UTC](https://forum.syncthing.net/t/how-to-prevent-devices-from-announcing-themselves-to-stdiscosrv-with-random-ports-in-addition-to-port-22000-while-nat-and-lan-discovery-are-already-disabled/22814/2 "2024-09-18T12:30:26Z")

</div>

Is your discovery server running behind a reverse proxy? Are there any NATs involved in this setup?

---

<div class="post-metadata">

### Author: ![firesnake](https://forum.syncthing.net/letter_avatar_proxy/v4/letter/f/dbc845/32.png) [@firesnake](https://forum.syncthing.net/u/firesnake)
#### Post date: [September 18, 2024, 12:33pm UTC](https://forum.syncthing.net/t/how-to-prevent-devices-from-announcing-themselves-to-stdiscosrv-with-random-ports-in-addition-to-port-22000-while-nat-and-lan-discovery-are-already-disabled/22814/3 "2024-09-18T12:33:36Z")

</div>

no, and no

---

<div class="post-metadata">

### Author: ![Nummer378](https://forum.syncthing.net/user_avatar/forum.syncthing.net/nummer378/32/5958_2.png) [@Nummer378](https://forum.syncthing.net/u/Nummer378)
#### Post date: [September 18, 2024, 12:49pm UTC](https://forum.syncthing.net/t/how-to-prevent-devices-from-announcing-themselves-to-stdiscosrv-with-random-ports-in-addition-to-port-22000-while-nat-and-lan-discovery-are-already-disabled/22814/4 "2024-09-18T12:49:07Z")

</div>

Is the affected device running on Windows by any chance?

I _think_ this is caused by TCP port reusing not being supported in the local interface, which causes syncthing to use a normal ephemeral port during announce. (Normally, syncthing would try to announce to the discovery server via the sync port, 22200). The discovery server records all ports used by the announcing device, which then causes the list to be filled with ephemeral ports.

The TCP port reusing may break for various reasons, but it tends to happen more on Windows machines.

If you want more data on this, I suggest enabling debug logging (dialer and discovery).

---

<div class="post-metadata">

### Author: ![firesnake](https://forum.syncthing.net/letter_avatar_proxy/v4/letter/f/dbc845/32.png) [@firesnake](https://forum.syncthing.net/u/firesnake)
#### Post date: [September 18, 2024, 1:11pm UTC](https://forum.syncthing.net/t/how-to-prevent-devices-from-announcing-themselves-to-stdiscosrv-with-random-ports-in-addition-to-port-22000-while-nat-and-lan-discovery-are-already-disabled/22814/5 "2024-09-18T13:11:59Z")

</div>

no, they’re linux. one some older fedora 22, one an oracle linux 7. see more details and logs on these threads

> [@Cannot get QUIC working at all](https://forum.syncthing.net/t/cannot-get-quic-working-at-all/22782/8):
>
> wait. I just re-tested using netcat and I am not receiving everything that I paste on one end. I need to dig what’s happening down at ip/udp level. I was fooled initially by only typing a few characters, but pasted a copy paste from a random webpage and not all text went through!

> [@Problem with Private Relay Server (persists)](https://forum.syncthing.net/t/problem-with-private-relay-server-persists/22781/3):
>
> Did you try running with -debug to see what it says? I can’t see anything hardcoded in the relay. Syncthing itself also has timeouts, as well as the kernel/os.

> [@Installation on hundreds of devices](https://forum.syncthing.net/t/installation-on-hundreds-of-devices/22717/3):
>
> forgot to mention that the files content will never modify, so rsync advantage of only differing blocks will not apply here. every now and then, a whole new file get introduced in the folder and older ones deleted.

---

<div class="post-metadata">

### Author: ![Nummer378](https://forum.syncthing.net/user_avatar/forum.syncthing.net/nummer378/32/5958_2.png) [@Nummer378](https://forum.syncthing.net/u/Nummer378)
#### Post date: [September 18, 2024, 1:15pm UTC](https://forum.syncthing.net/t/how-to-prevent-devices-from-announcing-themselves-to-stdiscosrv-with-random-ports-in-addition-to-port-22000-while-nat-and-lan-discovery-are-already-disabled/22814/6 "2024-09-18T13:15:13Z")

</div>

Yeah, I think one of the announced addresses contains a 0 port for whatever reason, which is then replaced by the actual remote port in stdiscosrv, which doesn’t work properly if the dialer uses ephemeral ports.

Debug logging will probably show what’s going on.

---

<div class="post-metadata">

### Author: ![firesnake](https://forum.syncthing.net/letter_avatar_proxy/v4/letter/f/dbc845/32.png) [@firesnake](https://forum.syncthing.net/u/firesnake)
#### Post date: [September 18, 2024, 1:16pm UTC](https://forum.syncthing.net/t/how-to-prevent-devices-from-announcing-themselves-to-stdiscosrv-with-random-ports-in-addition-to-port-22000-while-nat-and-lan-discovery-are-already-disabled/22814/7 "2024-09-18T13:16:31Z")

</div>

I am already running in debug logging but see nothing about extra ports being announced. right now I’m struggling to setup a reverse proxy in front of stdiscosrv to be able to capture plain http traffic between the reverse and discovery server. unfortunately stdiscosrv tells nothing relevant in -debug mode

---

<div class="post-metadata">

### Author: ![firesnake](https://forum.syncthing.net/letter_avatar_proxy/v4/letter/f/dbc845/32.png) [@firesnake](https://forum.syncthing.net/u/firesnake)
#### Post date: [September 18, 2024, 1:27pm UTC](https://forum.syncthing.net/t/how-to-prevent-devices-from-announcing-themselves-to-stdiscosrv-with-random-ports-in-addition-to-port-22000-while-nat-and-lan-discovery-are-already-disabled/22814/8 "2024-09-18T13:27:46Z")

</div>

yes, wireshark confirms announcing port 0

```plaintext
JavaScript Object Notation: application/json
    Object
        Member Key: "addresses"
            Array
                String value: tcp4://0.0.0.0:0
                String value: tcp4://:22000

```

---

<div class="post-metadata">

### Author: ![firesnake](https://forum.syncthing.net/letter_avatar_proxy/v4/letter/f/dbc845/32.png) [@firesnake](https://forum.syncthing.net/u/firesnake)
#### Post date: [September 18, 2024, 1:30pm UTC](https://forum.syncthing.net/t/how-to-prevent-devices-from-announcing-themselves-to-stdiscosrv-with-random-ports-in-addition-to-port-22000-while-nat-and-lan-discovery-are-already-disabled/22814/9 "2024-09-18T13:30:34Z")

</div>

client config is in first post from here [Cannot get QUIC working at all](https://forum.syncthing.net/t/cannot-get-quic-working-at-all/22782) with current modifications that I also set

`announceLANAddresses` is false

`natEnabled` is false

and changed back from non-working quic to tcp4

---

<div class="post-metadata">

### Author: ![firesnake](https://forum.syncthing.net/letter_avatar_proxy/v4/letter/f/dbc845/32.png) [@firesnake](https://forum.syncthing.net/u/firesnake)
#### Post date: [September 18, 2024, 1:34pm UTC](https://forum.syncthing.net/t/how-to-prevent-devices-from-announcing-themselves-to-stdiscosrv-with-random-ports-in-addition-to-port-22000-while-nat-and-lan-discovery-are-already-disabled/22814/10 "2024-09-18T13:34:54Z")

</div>

found the debug line where it announces port 0 despite explicit tcp4 hostname:port pair defined in `listenAddress`

`Sep 18 16:32:53 t00901 syncthing[17372]: [N74QT] DEBUG: global@https://rsync:8443/v2/ Announcement: {[tcp4://0.0.0.0:0 tcp4://t00901:22000]}`

---

<div class="post-metadata">

### Author: ![firesnake](https://forum.syncthing.net/letter_avatar_proxy/v4/letter/f/dbc845/32.png) [@firesnake](https://forum.syncthing.net/u/firesnake)
#### Post date: [September 18, 2024, 1:40pm UTC](https://forum.syncthing.net/t/how-to-prevent-devices-from-announcing-themselves-to-stdiscosrv-with-random-ports-in-addition-to-port-22000-while-nat-and-lan-discovery-are-already-disabled/22814/11 "2024-09-18T13:40:06Z")

</div>

and debug logs again to save you digging the other thread

```plaintext
[user@T00901 ~]$ export STTRACE=connections,dialer,discover,nat,upnp,protocol,net,beacon,relay
[user@T00901 ~]$ export QUIC_GO_LOG_LEVEL=DEBUG
[user@T00901 ~]$ /usr/local/bin/syncthing serve --no-upgrade --no-browser --no-restart
2024/09/18 16:38:20.440367 control_unix.go:35: DEBUG: SO_REUSEPORT supported
2024/09/18 16:38:20.464097 control_unix.go:35: DEBUG: SO_REUSEPORT supported
[start] 2024/09/18 16:38:20.473947 main.go:535: INFO: syncthing v1.27.11 "Gold Grasshopper" (go1.22.6 linux-amd64) builder@github.syncthing.net 2024-08-28 06:32:03 UTC
[start] 2024/09/18 16:38:20.508937 main.go:761: INFO: No automatic upgrades; STNOUPGRADE environment variable defined.
[N74QT] 2024/09/18 16:38:20.510140 syncthing.go:155: INFO: My ID: N74QTL7-GVVDDQK-OPTDSXQ-DEGHCK7-ZB7VPOS-ZIKWZJ5-5WKHG3L-2SGOVAK
[monitor] 2024/09/18 16:38:20.940967 internal.go:44: DEBUG: Dialer logging disabled, as no proxy was detected
[N74QT] 2024/09/18 16:38:20.965567 internal.go:44: DEBUG: Dialer logging disabled, as no proxy was detected
[N74QT] 2024/09/18 16:38:21.012429 syncthing.go:182: INFO: Hashing performance is 61.40 MB/s
[N74QT] 2024/09/18 16:38:21.013031 limiter.go:109: INFO: Device ONX5KQ3-ST4PELN-EOLR4GG-KUDGPX3-2NCAABW-HZQKYU3-SQB75N2-YGLH7QZ send rate is unlimited, receive rate limit is 3 KiB/s
[N74QT] 2024/09/18 16:38:21.013095 limiter.go:162: INFO: Overall send rate is unlimited, receive rate limit is 3 KiB/s
[N74QT] 2024/09/18 16:38:21.013113 limiter.go:168: INFO: Rate limits do not apply to LAN connections
[N74QT] 2024/09/18 16:38:21.013428 service.go:818: DEBUG: Starting listener tcp4://t00901:22000
[N74QT] 2024/09/18 16:38:21.014081 manager.go:92: INFO: Using discovery mechanism: global discovery server https://rsync:8443/v2/?id=QKNYIZC-RIY7HKO-GGL6TQA-F7IK6EO-JFRIMGU-NXW7TKS-54MUSD2-3IE43QZ
[N74QT] 2024/09/18 16:38:21.014200 model.go:415: INFO: Ready to synchronize "Default Folder" (default) (receiveonly)
[N74QT] 2024/09/18 16:38:21.015008 tcp_listen.go:77: INFO: TCP listener (10.x.x.x:22000) starting
[N74QT] 2024/09/18 16:38:21.015229 service.go:477: DEBUG: Connection loop
[N74QT] 2024/09/18 16:38:21.015290 service.go:479: DEBUG: Connection loop in initial rampup
[N74QT] 2024/09/18 16:38:21.016361 folder.go:925: INFO: Completed initial scan of receiveonly folder "Default Folder" (default)
[N74QT] 2024/09/18 16:38:21.016968 api.go:406: INFO: GUI and API listening on [::]:8384
[N74QT] 2024/09/18 16:38:21.017030 api.go:407: INFO: Access the GUI via the following URL: http://127.0.0.1:8384/
[N74QT] 2024/09/18 16:38:21.017130 syncthing.go:312: INFO: My name is "T00901"
[N74QT] 2024/09/18 16:38:21.017237 syncthing.go:315: INFO: Device ONX5KQ3-ST4PELN-EOLR4GG-KUDGPX3-2NCAABW-HZQKYU3-SQB75N2-YGLH7QZ is "rsync-stage" at [dynamic]
[N74QT] 2024/09/18 16:38:21.017282 syncthing.go:315: INFO: Device SXUMNJK-GUG632P-RONH6WD-WI6C6GT-QSEL5VZ-CEYHYTM-X6LF2K3-OOB6VQJ is "T00901" at [dynamic]
[N74QT] 2024/09/18 16:38:21.017319 syncthing.go:315: INFO: Device 36J46B5-NVJFLWX-N3A3JAE-ZBFM5V6-XKBINMT-JX6KZN4-MQXE5SA-UJIM6QX is "T00901" at [dynamic]
[N74QT] 2024/09/18 16:38:21.483847 public.go:74: DEBUG: Dialing direct result tcp rsync:8443: &{{0xc00032e200}} <nil>
[N74QT] 2024/09/18 16:38:22.263831 global.go:186: DEBUG: globalClient.Lookup https://rsync:8443/v2/?device=ONX5KQ3-ST4PELN-EOLR4GG-KUDGPX3-2NCAABW-HZQKYU3-SQB75N2-YGLH7QZ 404 Not Found
[N74QT] 2024/09/18 16:38:22.264328 manager.go:164: DEBUG: lookup results for ONX5KQ3-ST4PELN-EOLR4GG-KUDGPX3-2NCAABW-HZQKYU3-SQB75N2-YGLH7QZ
[N74QT] 2024/09/18 16:38:22.264387 manager.go:165: DEBUG: addresses: []
[N74QT] 2024/09/18 16:38:22.264437 service.go:657: DEBUG: Resolved device ONX5KQ3 addresses: []
[N74QT] 2024/09/18 16:38:22.264499 service.go:507: DEBUG: Next connection loop in 5s
[N74QT] 2024/09/18 16:38:23.018495 global.go:273: DEBUG: global@https://rsync:8443/v2/ Announcement: {[tcp4://0.0.0.0:0 tcp4://t00901:22000]}
[N74QT] 2024/09/18 16:38:23.054146 public.go:74: DEBUG: Dialing direct result tcp rsync:8443: &{{0xc0005a2980}} <nil>
[N74QT] 2024/09/18 16:38:23.263935 global.go:282: DEBUG: global@https://rsync:8443/v2/ announce POST: 204 No Content
[N74QT] 2024/09/18 16:38:23.264137 global.go:309: DEBUG: global@https://rsync:8443/v2/ announce Reannounce-After: 3373 <nil>
^C[monitor] 2024/09/18 16:38:25.210892 monitor.go:161: INFO: Signal 2 received; exiting
[N74QT] 2024/09/18 16:38:26.021916 tcp_listen.go:120: INFO: TCP listener (10.x.x.x:22000) shutting down
[N74QT] 2024/09/18 16:38:26.022683 syncthing.go:351: INFO: Exiting

```

---

<div class="post-metadata">

### Author: ![AudriusButkevicius](https://forum.syncthing.net/user_avatar/forum.syncthing.net/audriusbutkevicius/32/277_2.png) [@AudriusButkevicius](https://forum.syncthing.net/u/AudriusButkevicius)
#### Post date: [September 18, 2024, 1:43pm UTC](https://forum.syncthing.net/t/how-to-prevent-devices-from-announcing-themselves-to-stdiscosrv-with-random-ports-in-addition-to-port-22000-while-nat-and-lan-discovery-are-already-disabled/22814/12 "2024-09-18T13:43:30Z")

</div>

We always add a :0 for good measure.

---

<div class="post-metadata">

### Author: ![firesnake](https://forum.syncthing.net/letter_avatar_proxy/v4/letter/f/dbc845/32.png) [@firesnake](https://forum.syncthing.net/u/firesnake)
#### Post date: [September 18, 2024, 1:44pm UTC](https://forum.syncthing.net/t/how-to-prevent-devices-from-announcing-themselves-to-stdiscosrv-with-random-ports-in-addition-to-port-22000-while-nat-and-lan-discovery-are-already-disabled/22814/13 "2024-09-18T13:44:00Z")

</div>

can it be disabled? this will multiply by hundreds of devices resulting in repeated loops of tcp resets, and that would be anything but “good measure” for my network

---

<div class="post-metadata">

### Author: ![AudriusButkevicius](https://forum.syncthing.net/user_avatar/forum.syncthing.net/audriusbutkevicius/32/277_2.png) [@AudriusButkevicius](https://forum.syncthing.net/u/AudriusButkevicius)
#### Post date: [September 18, 2024, 3:50pm UTC](https://forum.syncthing.net/t/how-to-prevent-devices-from-announcing-themselves-to-stdiscosrv-with-random-ports-in-addition-to-port-22000-while-nat-and-lan-discovery-are-already-disabled/22814/14 "2024-09-18T15:50:10Z")

</div>

You can’t. It’s 2 packets, not sure why you are so concerned.

---

<div class="post-metadata">

### Author: ![firesnake](https://forum.syncthing.net/letter_avatar_proxy/v4/letter/f/dbc845/32.png) [@firesnake](https://forum.syncthing.net/u/firesnake)
#### Post date: [September 18, 2024, 3:51pm UTC](https://forum.syncthing.net/t/how-to-prevent-devices-from-announcing-themselves-to-stdiscosrv-with-random-ports-in-addition-to-port-22000-while-nat-and-lan-discovery-are-already-disabled/22814/15 "2024-09-18T15:51:27Z")

</div>

it’s 2 packets multiplied by hundreds or more devices repeated all over. I need to reduce traffic to minimum because it’s a high latency low bandwith infrastructure

plus, I don’t think it’s normal for clients to search for each other on invalid ports in an infinite loop. at least open/bind to that port you are announcing.

---

<div class="post-metadata">

### Author: ![AudriusButkevicius](https://forum.syncthing.net/user_avatar/forum.syncthing.net/audriusbutkevicius/32/277_2.png) [@AudriusButkevicius](https://forum.syncthing.net/u/AudriusButkevicius)
#### Post date: [September 18, 2024, 4:00pm UTC](https://forum.syncthing.net/t/how-to-prevent-devices-from-announcing-themselves-to-stdiscosrv-with-random-ports-in-addition-to-port-22000-while-nat-and-lan-discovery-are-already-disabled/22814/16 "2024-09-18T16:00:34Z")

</div>

Feels like you need specialised software if you care about that. Syncthing chats quite a lot willy nilly, and priority is connectivity rather than minimal bandwidth.

---

<div class="post-metadata">

### Author: ![firesnake](https://forum.syncthing.net/letter_avatar_proxy/v4/letter/f/dbc845/32.png) [@firesnake](https://forum.syncthing.net/u/firesnake)
#### Post date: [September 18, 2024, 4:05pm UTC](https://forum.syncthing.net/t/how-to-prevent-devices-from-announcing-themselves-to-stdiscosrv-with-random-ports-in-addition-to-port-22000-while-nat-and-lan-discovery-are-already-disabled/22814/17 "2024-09-18T16:05:45Z")

</div>

still remains a valid point that clients are instructed to connect to other clients to ports on which they don’t listen. that’s got nothing to do with being chatty, but sounds rather a design bug to me.

it’s like meeting a person and telling them call me on this number, and oh, look me up in the directory, but hey, you might find an invalid number of me there.

---

<div class="post-metadata">

### Author: ![AudriusButkevicius](https://forum.syncthing.net/user_avatar/forum.syncthing.net/audriusbutkevicius/32/277_2.png) [@AudriusButkevicius](https://forum.syncthing.net/u/AudriusButkevicius)
#### Post date: [September 18, 2024, 4:15pm UTC](https://forum.syncthing.net/t/how-to-prevent-devices-from-announcing-themselves-to-stdiscosrv-with-random-ports-in-addition-to-port-22000-while-nat-and-lan-discovery-are-already-disabled/22814/18 "2024-09-18T16:15:59Z")

</div>

Clients don’t know what ports the nat mapped for them, hence the notion of :0, which gets replaced by the outgoing connection port by the discovery server.

---

<div class="post-metadata">

### Author: ![Nummer378](https://forum.syncthing.net/user_avatar/forum.syncthing.net/nummer378/32/5958_2.png) [@Nummer378](https://forum.syncthing.net/u/Nummer378)
#### Post date: [September 18, 2024, 4:50pm UTC](https://forum.syncthing.net/t/how-to-prevent-devices-from-announcing-themselves-to-stdiscosrv-with-random-ports-in-addition-to-port-22000-while-nat-and-lan-discovery-are-already-disabled/22814/19 "2024-09-18T16:50:18Z")

</div>

So, as already mentioned port 0 gets replaced by the dialing (source) port of the announce, which _should_ be a valid port that syncthing also listens on (like 22000). This is done via TCP port reuse, so that the outgoing port is the same as the incoming port (i.e. you’ve both a TCP client and a TCP server socket on the same port). This causes the annoucement to be sent from port 22000, which your NAT might then remap to whatever. The discovery server records the NAT-mapped port so that hole punching knows where to knock.

In your case this goes wrong (which can happen due to unsupported operating systems, network interface or routing specifics), in that case syncthing falls back to letting the operating system choose an outgoing port. This port is obviously not setup for incoming connections, so it causes the behaviour you’re seeing. This is not the intended behaviour of the announcement, but rather the result of TCP port reusing not working properly for some reason.

There’s debug logging in syncthing which logs TCP port reuse problems, so data from that could help.

---

<div class="post-metadata">

### Author: ![firesnake](https://forum.syncthing.net/letter_avatar_proxy/v4/letter/f/dbc845/32.png) [@firesnake](https://forum.syncthing.net/u/firesnake)
#### Post date: [September 20, 2024, 11:21am UTC](https://forum.syncthing.net/t/how-to-prevent-devices-from-announcing-themselves-to-stdiscosrv-with-random-ports-in-addition-to-port-22000-while-nat-and-lan-discovery-are-already-disabled/22814/20 "2024-09-20T11:21:06Z")

</div>

> [@Nummer378](#):
>
> which your NAT might then remap

there is no nat involved. the nat is disabled in configuration. there is direct routing via isolated network. there is no relay enabled. there is no local announcement enabled. there is no firewall.

**it’s just plain simple host A to host B communication via standard router.**

I fail to see any logical reason to still announce :0 in this case.

[Next page](https://forum.syncthing.net/t/how-to-prevent-devices-from-announcing-themselves-to-stdiscosrv-with-random-ports-in-addition-to-port-22000-while-nat-and-lan-discovery-are-already-disabled/22814.md?page=2)
