News: This forum is now permanently frozen.
Pages: [1]
Topic: 1.3b9 default rules blocking VRRP/CARP traffic and cannot be overridden  (Read 4131 times)
« on: January 20, 2008, 12:33:39 »
cariafraweb *
Posts: 3

Hi,

I have configured a 1.3b9 as a filtered bridge using this guide:
http://doc.m0n0.ch/handbook/examples-filtered-bridge.html (I used 3 NICs and a standard PC with 16 MB CF and 1 GB RAM)

and everything works, except from one thing:

even if I create a new rule allowing all TCP traffic (I also tried using "any" but neither this worked) from 85.94.199.157 to 224.0.0.18 (this is the standard IP used to make VRRP work), the firewall log (of course after being cleared) still continues to grow saying that CARP (VRRP) traffic is being blocked

This is a screenshot of the log, with "Show raw filter logs" enabled
http://contenuti.francescocariati.net/varie/ishot-2.jpg

I also discovered that if I unset the "Log packets blocked by the default rule" option, the log stops growing, so I'm pretty sure that this VRRP traffic is being blocked by a m0n0wall default rule

The question is: how can I make this traffic pass the firewall?
Second question: what are the default m0n0wall rules in 1.3b9?

Thanks in advance
Best Regards
« Last Edit: January 20, 2008, 12:35:32 by cariafraweb »
« Reply #1 on: January 20, 2008, 21:03:43 »
cmb *****
Posts: 851

VRRP traffic isn't TCP, it's its own IP protocol. You should be able to use protocol "any" to pass it.
« Reply #2 on: January 21, 2008, 12:16:39 »
cariafraweb *
Posts: 3

I also tried "any" but I'm sure it didn't work (log continued to grow)
« Reply #3 on: February 07, 2008, 11:43:18 »
BENtheTEN *
Posts: 4

Hi I have the same problem, it doesn't matter what rule I add (normaly pass any any any * * whatever) m0n0 wall keeps blocking some traffic by the default rule, which doesn't seem possible to be disabled.

I have no idea what rule could help
« Reply #4 on: March 02, 2008, 12:59:59 »
cariafraweb *
Posts: 3

I still have this problem Sad

Ideas?

Best Regards
 
Pages: [1]
 
 
Powered by SMF 1.1.20 | SMF © 2013, Simple Machines