News: This forum is now permanently frozen.
Pages: [1]
Topic: Can't catch traffic with filter (v1.33)  (Read 1021 times)
« on: March 26, 2011, 23:56:06 »
m0n0b0b *
Posts: 9

I have WAN and LAN. Some LAN machines open outgoing TCP connections (port 445) which I would like to block.

So, in the LAN interface, I added a first rule, for any source to WAN:445 to block+log. However, I don't see anything logged, and connections are still created. This is frustrating because what I'm trying to do is very simple, but it just doesn't work.

One thing to note is that I have OPT1/2/3 configured to bridge with LAN. Perhaps, that's messing up the firewall?? At least for OPT1/2/3 I see a warning that "Firewall rules for an interface in bridged mode have no effect on packets to hosts other than m0n0wall itself" -- whatever this means... Should LAN still work?

Thanks.
« Reply #1 on: March 27, 2011, 00:24:48 »
Fred Grayson *****
Posts: 994

Probably a wrong filter specification. You are blocking packets destined for the WAN address on port 445, but this is probably not what you really want. Try changing the destination to any address and port 445.

--
Google is your friend and Bob's your uncle.
« Reply #2 on: March 27, 2011, 00:57:01 »
m0n0b0b *
Posts: 9

Embarassingly, yes, the problem was using "WAN address", which I thought for some reason was any WAN address instead of the assigned "external" WAN address. Works now, thanks!!!!
 
Pages: [1]
 
 
Powered by SMF 1.1.20 | SMF © 2013, Simple Machines