PDA

Bekijk de volledige versie : WAN to LAN Filter Problems



Shawn
28-12-2004, 00:57
Hello,

i am using Firmware 1.9.27 (original) and i have some problems at the point of creating some WAN to LAN Filter.

My Settings:
Enable WAN to LAN Filter?: YES
Date to Enable WAN to LAN Filter:: All days
Time of Day to Enable WAN to LAN Filter: All Time

Packets(WAN to LAN) not specified will be: DROP
Filtered ICMP(WAN to LAN) packet types: BLANK

WAN to LAN Filter Table:
SourceIP - PortRange - DestinationIP - PortRange - Protocol
*.*.*.* - 110 - *.*.*.* - 110 - TCP ALL
*.*.*.* - 25 - *.*.*.* - 25 - TCP ALL
*.*.*.* - 443 - *.*.*.* - 443 - TCP ALL
*.*.*.* - 20:21 - 192.168.100.1 - 25 - TCP ALL
*.*.*.* - 4661:4665 - 192.168.100.1 - 4661:4665 - TCP ALL
*.*.*.* - 4672 - 192.168.100.1 - 4672 - UDP
*.*.*.* - 80 - *.*.*.* - 80 - TCP ALL

If i press APPLY and RESTART after that i cant open any URL! Server is not reachable! I cant also get any mails through port 110 and 25!

I think the setting are correct!

Oh i forgot!
Enable LAN to WAN Filter?: NO!

And some virtuell Server i have entered:
PortRange - LocalIP - Local Port - Protocol - ProtocolNo. - Description
110 - 192.168.100.3 - BLANK - BOTH - BLANK - blablabla
110 - 192.168.100.4 - BLANK - BOTH - BLANK - blablabla
25 - 192.168.100.3 - BLANK - BOTH - BLANK - blablabla
25 - 192.168.100.4 - BLANK - BOTH - BLANK - blablabla
20:21 - 192.168.100.1 - BLANK - BOTH - BLANK - blablabla
4661:4665 - 192.168.100.1 - BLANK - TCP - BLANK - blablabla
4672 - 192.168.100.1 - BLANK - UDP - BLANK - blablabla


What is wrong at my settings that nothing will work after enable WAN to LAN Filter?
Many Thx for helping me with this problem!

Shawn

MAV
28-12-2004, 10:59
if you read
http://wl500g.info/showthread.php?t=1344 & another Thread dedicate
Firewall setting.

you can obtain secret knowledge that this stupid WLAN 2 LAN 2 WLAN filtration does'nt work in any combination.
Forget about this thing :)
sorry for my bad language

Oleg
28-12-2004, 11:11
WAN to LAN Filter Table:
SourceIP - PortRange - DestinationIP - PortRange - Protocol
*.*.*.* - 110 - *.*.*.* - 110 - TCP ALL
*.*.*.* - 25 - *.*.*.* - 25 - TCP ALL
*.*.*.* - 443 - *.*.*.* - 443 - TCP ALL
*.*.*.* - 20:21 - 192.168.100.1 - 25 - TCP ALL
*.*.*.* - 4661:4665 - 192.168.100.1 - 4661:4665 - TCP ALL
*.*.*.* - 4672 - 192.168.100.1 - 4672 - UDP
*.*.*.* - 80 - *.*.*.* - 80 - TCP ALL

You do not need to specify Destination port like this, leave it blank.

Shawn
28-12-2004, 14:24
What a shity router?
Whats that!
There is a point to select some definitions and it doesnt work!

I cant believe!

Would this solve my problem i have read in the other thread!

iptables -I FORWARD -p 47 -j ACCEPT

If the answer is "YES" how can i get the hidden admin side?

Many ThX!

Shawn

wiz
28-12-2004, 14:37
What a shity router?
Whats that!
There is a point to select some definitions and it doesnt work!

I cant believe!

Would this solve my problem i have read in the other thread!

iptables -I FORWARD -p 47 -j ACCEPT

If the answer is "YES" how can i get the hidden admin side?

Many ThX!

Shawn

Huh?

What dit Oleg just said?

Oleg said leave destination portranges empty.
so the only thing you put in your wan to lan filter is the originating port you want to allow and whether it is a TCP or UDP port.

And this device is not a shity router just because you filled in something that makes no sence.

just my 2 cts.

Shawn
28-12-2004, 14:39
Sorry i didnt told that i tried to leave the fields blank!
Result.....: NOT WORKING!

So i am a little bit frustrated about this!

Shawn

I tried several entries.

1. BLANK - 80 - 192.168.100.* - 80 - TCP ALL
2. BLANK - 80 - BLANK - 80 - TCP ALL

Oleg
28-12-2004, 14:51
Flash 1.9.2.7-2, it should work fine with no WAN to LAN rules.

Styno
28-12-2004, 14:52
What a shity router?Your opinion

Whats that!
There is a point to select some definitions and it doesnt work!Yes, Asus is a consumer product, hence it has flaws, but mostly: "The source of the problem lies between the computer screen and the chair".


I cant believe!

Would this solve my problem i have read in the other thread!

iptables -I FORWARD -p 47 -j ACCEPT

If the answer is "YES" how can i get the hidden admin side?

Many ThX!That might be the problem, seach this forum for hidden admin page and you will find a link.

Thanks for your patience ;)

Shawn
28-12-2004, 15:14
@Oleg

But i want to have WAN 2 LAN Rulez!

I dont want to change the firmware and working without WAN 2 LAN Rulez!
Have you any other idea??

Many ThX!

I try to search for hidden admin page!

Shawn

OK Hidden Admin Page found!! THX! Sorry i have to use "SEARCH" Button!
But i have entered the Sentences and nothing happend!

Result: NOT WORKING!

wiz
28-12-2004, 15:14
Sorry i didnt told that i tried to leave the fields blank!
Result.....: NOT WORKING!

So i am a little bit frustrated about this!

Shawn

I tried several entries.

1. BLANK - 80 - 192.168.100.* - 80 - TCP ALL
2. BLANK - 80 - BLANK - 80 - TCP ALL

hmmz. Howcome I still see originating ports and destination ports filled in here then?

try something like this:

1. BLANK - 80 - 192.168.100.* - BLANK - TCP ALL
2. BLANK - 80 - BLANK - BLANK - TCP ALL[/QUOTE]

the first line however will only allow port 80 from 192.168.100.*. If this is a filter from wan to lan, it doesn't make sense unless yr asus is hooked up to another router that is in the 192.168.100.* range.

second line allows port 80 to go through originating from any host. Makes more sence.

For wan to lan filters, you only specify what source ip or port you want to allow, the destination isn't specified.

Shawn
28-12-2004, 15:27
OK That sounds plausible!

I try it!

Many Thx!

Shawn

Shawn
28-12-2004, 15:34
Sorry didnt worked!

I tried these....

BLANK - 80 - BLANK - BLANK - TCP ALL

And that was the result in System Log!

Dec 28 04:19:49 filter: TCP connection denied to xx.xx.xx.xx:445 from xx.xx.xx.x:1702
Dec 28 04:19:50 filter: UDP connection denied to 192.168.100.1:4672 from xx.xxx.xxx.xxx:5672
Dec 28 04:20:05 filter: TCP connection denied to xx.xx.xx.xxx:135 from xx.xx.xx.xxx:1563

Why these Ports?

Oleg
28-12-2004, 15:35
Do you've LAN to WAN filter enabled? If so, disable it before testing WAN to LAN. Once WAN to LAN stuff starts working you can try LAN to WAN.

Shawn
28-12-2004, 15:42
@Oleg.

No i have disabled LAN 2 WAN Filter!
I tried only WAN 2 LAN and this problem is big enough!

Shawn

wiz
28-12-2004, 15:45
Sorry didnt worked!

I tried these....

BLANK - 80 - BLANK - BLANK - TCP ALL

And that was the result in System Log!

Dec 28 04:19:49 filter: TCP connection denied to xx.xx.xx.xx:445 from xx.xx.xx.x:1702
Dec 28 04:19:50 filter: UDP connection denied to 192.168.100.1:4672 from xx.xxx.xxx.xxx:5672
Dec 28 04:20:05 filter: TCP connection denied to xx.xx.xx.xxx:135 from xx.xx.xx.xxx:1563

Why these Ports?

I assume you put the wan 2 lan filter on drop if not on list? then everything that is not on the list will be blocked. So if you only allow port 80 to go through everything else will get blocked. Your firewall works!

And like Oleg said, first try wan 2 lan and then if you want the lan 2 wan filters

Shawn
28-12-2004, 15:57
@wiz

Ok Firewall works but why i couldnt get into the web after enable WAN 2 LAN Filters!
All Ports i needed are described in my WAN 2 LAN Filters and LAN 2 WAN is disabled!

Shawn

Here is a hardcopy of my selections!
A little bit deeper there is also Port 80 (BLANK - 80 - BLANK - BLANK - TCP ALL). You couldnt see it on this picture!

wiz
28-12-2004, 16:03
have a look at my screenshot:

screenshot (http://www.wizhost.demon.nl/scrshot.jpg)

this is how my wan 2 lan is set up.

Shawn
28-12-2004, 16:08
Thats my problem Wiz!

If i enable WAN 2 LAN Filter and the settings are.....

BLANK - 80 - BLANK - BLANK - TCP ALL

I didnt come into the web!

Shawn

Shawn
28-12-2004, 16:13
I found the problem!

Its not TCP ALL!

ITS only TCP!

That was the problem!

Now it works for web and i will try the other entries!

Shawn

Shawn
28-12-2004, 17:06
Now i have a new problem!

All ports are working fine!

Port 110
Port 25
Port 20:21
Port 443
Port 123 and
Port 53

but i have a problem with these ports for my eMule!
4661:4665
4672


Could anybody help me with this last WAN 2 LAN Problem?

Many ThX!

Jeroen Vonk
28-12-2004, 19:45
I think you should also add 4673 (both tcp and udp) for kademlia to work.... (or is that not your problem?)

Shawn
28-12-2004, 23:20
No thats not my problem!

Kad is still connecting, but eMule will not connect!

Many ThX!

Shawn

Jeroen Vonk
29-12-2004, 08:00
I've got it like this, and it's working. (currently using 1.9.2.7-2, with 1.8.x.x is was also working)

Shawn
29-12-2004, 08:46
Many ThX for your answer Vonk!

I will try it!

Shawn

P.S. Your are using 1.9.2.7-2!
It is possible to downgrade to 1.9.2.7 if i try 1.9.2.7-2?

Antiloop
29-12-2004, 09:24
Many ThX for your answer Vonk!

I will try it!

Shawn

P.S. Your are using 1.9.2.7-2!
It is possible to downgrade to 1.9.2.7 if i try 1.9.2.7-2?
you can just downgrade to 1.9.2.7 yes

opg2000
15-05-2005, 14:46
[QUOTE=Shawn]
I will try it!

Shawn
-----------------------------------
...have you tied it?
Any results?
I have the same problem with the WAN 2 LAN filtering.
My firm. is 1.9.2.7 -5
:confused:
lg opg

-----

emo
20-05-2005, 09:07
http://home.no.net/emo/lan2wan.jpg

This screen-grab shows what I have tried after reading this thread.
What I actually want to achieve is to stop all access to Internet no matter what during a given period of time.

How do I do this?