News
:
This forum is now permanently frozen.
m0n0wall Forum
>
m0n0wall Support (English)
>
Firewall/NAT
Topic: People on the Internet not able to reach OPT1 Network.
Pages: [
1
]
Topic: People on the Internet not able to reach OPT1 Network. (Read 1981 times)
People on the Internet not able to reach OPT1 Network.
« on: March 15, 2008, 23:48:29 »
DoyleChris
Posts: 7
I have a Server im trying to run Webserver and a FTP server and also a few game servers on (Americas Army and Call of Duty 4) I am trying to get Americas Army to run right now and no luck. Hear is a picture of the network, my rules and nat rules. If anybody can help me out it would be great.
(http://i198.photobucket.com/albums/aa132/DoyleChris/Network.jpg)(http://i198.photobucket.com/albums/aa132/DoyleChris/RULES.jpg)(http://i198.photobucket.com/albums/aa132/DoyleChris/NAT.jpg)
Re: People on the Internet not able to reach OPT1 Network.
« Reply #1 on: March 20, 2008, 10:32:32 »
markb
Posts: 331
Hi, Nice clear pictures, thanks. The rules look to be set up correctly. Is there any evidence of dropped traffic in the Logs? Have you got the rules to let traffic out from the Opt1 interface? How are you testing this? You are aware that you will not be able to access NAT'd services from the LAN using the WAN IP address aren't you?
A side note. It is good practice to have a block all rule at the bottom of your WAN rules to explicitly block all other traffic.
Re: People on the Internet not able to reach OPT1 Network.
« Reply #2 on: March 20, 2008, 18:51:16 »
ChainSaw
Guest
Quote from: markb on March 20, 2008, 10:32:32
A side note. It is good practice to have a block all rule at the bottom of your WAN rules to explicitly block all other traffic.
Would you mind explaining what the purpose of this last block rule was.
CS...
Re: People on the Internet not able to reach OPT1 Network.
« Reply #3 on: March 25, 2008, 10:15:11 »
markb
Posts: 331
Although monowall will block all traffic not explicitly allowed through, having a block all rule at the bottom of your rules is good practice to be sure that you are blocking all undesirable traffic. It is also useful if you have to start investigating the logs as you can turn logging off for the blocked traffic if you need to trace a problem. Without the rule, all blocked traffic will be recorded in the logs and you will not be able to stop the logging if you need to. I only mentioned it as good practice not because it was absolutely necessary.
Re: People on the Internet not able to reach OPT1 Network.
« Reply #4 on: March 25, 2008, 18:28:41 »
ChainSaw
Guest
that all makes good sense.
Thanks!
CS...
Pages: [
1
]