News: This forum is now permanently frozen.
Pages: [1]
Topic: Enable rule - Disable rule - but rule is still working...  (Read 5941 times)
« on: January 11, 2008, 10:24:07 »
manspan *
Posts: 10

I've created multiple VLANs on one NIC and then added firewall rules.
One of this rules, on VLAN50, is the following:
PROTO:ICMP
SOURCE:LAN50net
PORT:*
DESTINATION:195.xxx.xxx.xxx
PORT:*
With that rule I allow ping to destination 195.xxx.xxx.xxx
before "APPLY CHANGES", ping is not working (OK)
after "APPLY CHANGES" ping is working (OK)
Then I disable the rule and "APPLY CHANGES" and ping is still working (NOT OK)
In order to really apply changes I have to rebbot m0n0wall (ver 1.232 for generic-pc).
Is it a bug, or I miss something?

« Reply #1 on: January 11, 2008, 12:27:05 »
manspan *
Posts: 10

The rule has been finally applied after an 1hour and 10 minutes delay...
« Reply #2 on: January 13, 2008, 11:13:05 »
Max2950 ***
Posts: 120

I guess that some states do not get reset in the firewall after applying the rule.....
« Reply #3 on: January 14, 2008, 08:17:23 »
manspan *
Posts: 10

Instead of icmp I've tried http and it's working just fine.
I'll try all the protocols I'm interesting in, just to be sure...
m0n0wall is great anyway!



I don't think its stateful filtering.
I stoped ping then started again.
After a while started and stoped again
and again and again ...
« Last Edit: January 25, 2008, 08:37:47 by manspan »
« Reply #4 on: January 14, 2008, 17:37:11 »
Manuel Kasper
Administrator
*****
Posts: 364

This is normal behavior; existing connections are not affected by changes to firewall rules (stateful filtering). If you want to kill existing connections without rebooting, you can use the "Reset state" page.
 
Pages: [1]
 
 
Powered by SMF 1.1.20 | SMF © 2013, Simple Machines