(the only major configuration I've done in LEDE is to connect the WAN side (WWAN) through 4G/NCM and I also have one disabled port mapping rule that I enable sometimes)
Initiating Service scan at 15:29
...
PORT STATE SERVICE VERSION
7/tcp open tcpwrapped
9/tcp open discard?
13/tcp open daytime?
21/tcp open ftp?
22/tcp open tcpwrapped
23/tcp filtered telnet
25/tcp filtered smtp
26/tcp open rsftp?
37/tcp open time?
53/tcp filtered domain
79/tcp open tcpwrapped
80/tcp open tcpwrapped
81/tcp open hosts2-ns?
88/tcp open kerberos-sec?
106/tcp open tcpwrapped
110/tcp open pop3?
111/tcp closed rpcbind
113/tcp open tcpwrapped
119/tcp open nntp?
135/tcp filtered msrpc
139/tcp open netbios-ssn?
143/tcp closed imap
144/tcp open news?
179/tcp open tcpwrapped
199/tcp open tcpwrapped
389/tcp open ldap?
427/tcp open svrloc?
443/tcp filtered https
444/tcp open snpp?
445/tcp open microsoft-ds?
465/tcp open smtps?
513/tcp open tcpwrapped
514/tcp open shell?
515/tcp open printer?
543/tcp open klogin?
544/tcp filtered kshell
548/tcp open afp?
554/tcp open rtsp?
587/tcp open tcpwrapped
631/tcp open tcpwrapped
646/tcp open tcpwrapped
873/tcp open tcpwrapped
990/tcp open tcpwrapped
993/tcp closed imaps
995/tcp open tcpwrapped
1025/tcp closed NFS-or-IIS
1026/tcp open tcpwrapped
1027/tcp filtered IIS
1028/tcp open tcpwrapped
1029/tcp open tcpwrapped
1110/tcp open tcpwrapped
1433/tcp open tcpwrapped
1720/tcp open tcpwrapped
1723/tcp closed pptp
1755/tcp open tcpwrapped
1900/tcp open tcpwrapped
2000/tcp open tcpwrapped
2001/tcp filtered dc
2049/tcp open tcpwrapped
2121/tcp open tcpwrapped
2717/tcp open tcpwrapped
3000/tcp open tcpwrapped
3128/tcp open tcpwrapped
3306/tcp open tcpwrapped
3389/tcp closed ms-wbt-server
3986/tcp open tcpwrapped
4899/tcp open tcpwrapped
5000/tcp open tcpwrapped
5009/tcp open tcpwrapped
5051/tcp open tcpwrapped
5060/tcp open tcpwrapped
5101/tcp open tcpwrapped
5190/tcp open tcpwrapped
5357/tcp open tcpwrapped
5432/tcp open tcpwrapped
5631/tcp open tcpwrapped
5666/tcp open tcpwrapped
5800/tcp open tcpwrapped
5900/tcp closed vnc
6000/tcp open tcpwrapped
6001/tcp open tcpwrapped
6646/tcp open tcpwrapped
7070/tcp open tcpwrapped
8000/tcp open tcpwrapped
8008/tcp open tcpwrapped
8009/tcp open tcpwrapped
8080/tcp open tcpwrapped
8081/tcp open tcpwrapped
8443/tcp open tcpwrapped
8888/tcp open tcpwrapped
9100/tcp open jetdirect?
9999/tcp open tcpwrapped
10000/tcp filtered snet-sensor-mgmt
32768/tcp open tcpwrapped
49152/tcp open tcpwrapped
49153/tcp open tcpwrapped
49154/tcp open tcpwrapped
49155/tcp open tcpwrapped
49156/tcp open tcpwrapped
49157/tcp open tcpwrapped
Good question, as those ports are not open with the default config.
My first guess is that you do not actually have a public IP, but your 4G modem actually gives you a private IP inside ISP's NAT. And then the scan results would show upstream situation, not your own. Just check that you wwan really has a public IP, so that the scan is about you. (many ISPs give only private IPs to 3G/4G modems)
I adjusted my settings to match yours (reject becomes drop and disabled ping) but I still get the same result with open ports (on speedguide also).
Hm, I'm wondering if my 4G ISP could be doing something funky. I need to investigate more. Do you guys have some things that could be interesting to try?
Quite possible.
Your "public IP" looks like some kind of tunnel, as your netmask is so narrow that it only allows 2 bits for the addresses, meaning in practice just two addresses (01, 10) as 00 and 11 are not allowed.