News: This forum is now permanently frozen.
Pages: [1]
Topic: Which firewall rules are static/default/hidden?  (Read 2252 times)
« on: November 11, 2007, 04:36:51 »
LifeBoy *
Posts: 13

I'm really frustrated with m0n0wall.  I've been trying for two days to get a VPN tunnel or routing going between two LANs over a public internet link, but it only works partially.

There seem to be firewall rules that are not shown in the GUI.  They also don't seem to be documented anywhere?  Below is a drawing what I'm hoping to achieve:

(http://www.thegreentree.za.net-a.googlepages.com/M0n0wall_network.png)
I either want to route between the two networks.  This is already done, since the SP is routing the two private subnets between the two networks.  The default route in each is the LAN port on m0n0wall.  However, m0n0wall just doesn't allow certain types of traffic it seems: windows netbios packets, certain ICMP's, and maybe more.  No matter which rules I add, even routes as described elsewhere to allow SMNP via IPsec don't help.

Alternatively I tried an IPsec tunnel.  It gets established, but again I cannot browse from one network to the other. 

Can some explain what is happening here? 

I'm now setting up OpenVPN, which according to the some documentation is somewhere in m0n0wall as well, although I can't find it in 1.231 or 1.23.   So I'm just setting up to run on one machine each side in bridged mode and then I'll set a route in m0n0wall each side to that machine (since my default routes are the LAN ports on m0n0wall as shown in the diagram)

Is this possible?  If not, can a note be added to the documentation explaining that this cannot be done, or of course if it is possible, I'd gladly write a howto (once I get it going) to be included in the docs.

thanks


* M0n0wall_network.png (12.38 KB, 337x183 - viewed 312 times.)
« Reply #1 on: November 29, 2007, 13:06:27 »
dapi *
Posts: 3

First off .. I am super noob at this stuff so I might talk sh!t... if so sorry, just trying to help..
Ok here it goes;
Could it be the "Block private networks" option on the Interfaces > WAN -page ?
It's located at the bottom of the page.
« Reply #2 on: November 30, 2007, 10:41:58 »
markb ****
Posts: 331

By default, Monowall only logs traffic that is dropped by not fitting any rules.  If you wish to log other traffic, you need to check the box in the rules that you want to monitor to log the traffic.  As the built in log is not large, you may want to set up a syslog server and spit the logging out to it, giving yourself a fuller picture.  I have used wallwatcher successfully with Monowall and it's free.
« Reply #3 on: January 10, 2008, 17:06:10 »
LifeBoy *
Posts: 13

This issue was caused by the network provider doing NAT on their wireless routers.  Once that was turned off, the setup works 100%.   I have set up an IPSec tunnel and it was really a snap once the mentioned NAT was removed.
 
Pages: [1]
 
 
Powered by SMF 1.1.20 | SMF © 2013, Simple Machines