A quick port-scan against a Defend-O-Tron-protected router using GRC.com Shields Up shows the device's defense at work.

This report gives a full True Stealth rating — every probed port is blocked at the bridge before reaching the firewall, and the firewall/router itself refuses ICMP Echo. Your own report may vary depending on the ICMP configuration you use; ICMP is intentionally not part of the honeypot port list because it would interfere with Path MTU Discovery and IPv6 neighbour discovery.
If you see anything other than Stealth on a port that shouldn't be open, check the Honeypot page for the default port list, and check your firewall's port-forwarding rules for any rules that intentionally expose a service.