News: This forum is now permanently frozen.
Pages: [1]
Topic: m0n0wall blocks all traffic from WAN to LAN  (Read 1759 times)
« on: August 31, 2012, 17:33:18 »
Maerliprinz *
Posts: 1

Hello Community

My Setup: m0n0wall on x86 with 4 NIC's

fxp0 - OPT1 / OFF
fxp1 - WAN / 192.168.0.xxx/24 (DHCP from ISP, ISP = Fortigate FW)
fxp2 - OPT2 / OFF
fxp3 - LAN / 10.1.1.1/24

WAN Config:
IP: 192.168.0.25
GW: 192.168.0.1
DNS: 192.168.0.10 (DNS Server)

Client Config:
IP:10.1.1.101
GW, DHCP, DNS: 10.1.1.1

What I can from the Client:
Ping: 10.1.1.1, 192.168.0.1, 192.168.0.10, 208.67.222.222, google.com (is resolved to 173.194.35.9)
Windows 7 shows Client - Network - Internet Connection as good and working.

What I can't:
Open any Internet Site, resolve any public DNS Name in Browsers (IE, Firefox)

What I did:
Created Rule to Open any incomming traffic form WAN Interface ( Protocol: *, Source: WAN Adress, Port: *, Destination: *, Port: *)
Left the defaul Rule LAN to any actice
Removed the "Block private Networks" Rule

What I know:
In the Firewall Log it reports that Traffic from WAN like 173.194.35.31:80 to 10.1.1.101:54486 is blocked
The Log fills up 20 -30 Entrys per Minute if i try to connect to google.
The Browser can connect and get stucked while waiting for data from the Internetsite

What do I do wrong? Where is the mistake?

I already rebooted, resetted, reinstalled the m0nowall without any success  Sad


Acording to my understanding it should work but the WAN to LAN Traffic is somehow blocked
« Reply #1 on: August 31, 2012, 19:44:36 »
Fred Grayson *****
Posts: 994

In Interfaces: WAN scroll down to the bottom of the page. Make sure you untick Block private networks then hit the Save button.


Your rule: WAN Interface ( Protocol: *, Source: WAN Adress, Port: *, Destination: *, Port: *)

Never do this, it disables the firewall.

--
Google is your friend and Bob's your uncle.
 
Pages: [1]
 
 
Powered by SMF 1.1.20 | SMF © 2013, Simple Machines