How to disable TR-069 (aka CWMP) access to my FIOS router?
greenwave_rtr
Enthusiast - Level 1
I own my own FIOS Quantum Gateway Router model G1100 (purchased from Amazon).
 
But Verizon can apparently access it, thru its ACS (auto-configuration servers) based on the TR-069 protocol (aka CWMP protocol).
 
Is there a way to disable such access from within the Quantum Gateway router? I could not find anyway to do it after logging into my router. The router manual has no answer.
 
No one at Verizon can answer this question either.
 
0 Likes
Re: How to disable TR-069 (aka CWMP) access to my FIOS router?
smith6612
Community Leader
Community Leader

Typically it is not possible to disable TR-069 so long as a router is running the ISP branded firmware. You may be able to firewall off Port 4567 by creating a custom firewall rule, while the router is disconnected from the Internet, which disables the ability for the router to be managed in most cases. That won't prevent it from phoning home, which is typically handled via HTTPS.

The sure free way to remove TR-069 from your network is to use a third party router, which works if you only pay for Internet access.

Re: How to disable TR-069 (aka CWMP) access to my FIOS router?
greenwave_rtr
Enthusiast - Level 1

Also found some old instruction from https://gist.github.com/jgeboski/8468128

But it does not seem to work anymore. 

G1100 does not seem to even support telnet connection. 

0 Likes
Re: How to disable TR-069 (aka CWMP) access to my FIOS router?
smith6612
Community Leader
Community Leader

G1100 should support SSH. I believe it can be enabled from the Advanced > Remote Administration section still. SSH may have the same command available.