News: This forum is now permanently frozen.
Pages: [1]
Topic: Nothing Fancy Internal Static Route traffic being blocked  (Read 1391 times)
« on: December 16, 2008, 21:01:21 »
COMON$ *
Posts: 5

I have been beating my head over this issue.  It is either my own misunderstanding of how routing works or something is amiss in the m0nowall.

I have a WAN and a LAN.
Lan interface = 192.168.20.190
Wan interface = 76.79.56.178

There is a Fortigate attached to a switch on the 20.X network.  It routes to 5 different subnets. 10,20,30,40,50 and works great. 

I have a static route in the m0n0wall  LAN 192.168.10.0/24 ->192.168.20.254.
my firewall rules on the LAN interface are:

   *    192.168.20.0/24    *    *    *         

   *    192.168.10.0/24    *    *    *     
However in my logs I am getting allows and denies all over the place.  I can tracert and ping to the .10 network just fine.  Any other traffic gets denied by the default rule I imagine.  I am logging both firewall rules and I can see the allow happen, but right after there is a deny for the same rule. 
So somehow the default policy is denying all LAN traffic to the different subnet.

On a side note, when I removed all the LAN rules, I was still able to route properly after applying the deleted rules.  When I rebooted I was no longer able to route....just an oddity, probably a bug.


Edit:  It appears that the rules I create are allowing the traffic, but the next log shows them being denied.  How do I override the default rule in this scenario?
« Last Edit: December 16, 2008, 23:09:51 by COMON$ »
« Reply #1 on: December 16, 2008, 22:31:18 »
COMON$ *
Posts: 5

Ok solution kinda found.  In the advanced section of the firewall I checked the box for Bypassing firewall rules.  This checkbox evidentally is there because the firewall rules defined by the user do not override the default ones.  Oh well I cant see a reason you would filter them here anyway.

Bypass firewall rules for traffic on the same interface
This option only applies if you have defined one or more static routes. If it is enabled, traffic that enters and leaves through the same interface will not be checked by the firewall. This may be desirable in some situations where multiple subnets are connected to the same interface.
 
Pages: [1]
 
 
Powered by SMF 1.1.20 | SMF © 2013, Simple Machines