News: This forum is now permanently frozen.
Pages: [1]
Topic: Internal blocking rules not working  (Read 1203 times)
« on: September 21, 2012, 20:15:33 »
morthawt *
Posts: 20

I have tried to make it to ports 137-139 TCP/UDP are blocked when someone on my internal network tries to contact my machines IP with those ports. I have been unsucessful even though the rules look perfect. I did a test with blocking ICMP and while I can get it to fail to ping google from another ip, I cannot prevent it pinging my real machine, even with a rule that says any ICMP on lan net to lan net is blocked. No effect.

What am I doing wrong?
« Reply #1 on: September 21, 2012, 22:29:25 »
Fred Grayson *****
Posts: 994

If all of the machines are on the same network, then m0n0wall is not involved with any communications between those machines. All the traffic is handled by your switch - it never reaches m0n0wall.

--
Google is your friend and Bob's your uncle.
« Reply #2 on: September 21, 2012, 22:49:16 »
morthawt *
Posts: 20

Well the developers might want to include a check for that because it let me make lan to lan rules and appeared as if I had control over internal communication when in fact those rules were totally useless. Unless there is some other reason to make lan to lan rules I am unaware of?
« Reply #3 on: September 21, 2012, 23:15:16 »
Fred Grayson *****
Posts: 994

I have a hard time visualizing any product being encumbered to the degree required to flag every possible misconfiguration, as some fundamental understanding of networking is expected of the user. But that's just my opinion.

Feel free to make any suggestions in the Feature Requests area of the Forum.


--
Google is your friend and Bob's your uncle.
« Reply #4 on: September 22, 2012, 15:10:11 »
Јаневски ***
Posts: 153

Well the developers might want to include a check for that because it let me make lan to lan rules and appeared as if I had control over internal communication when in fact those rules were totally useless. Unless there is some other reason to make lan to lan rules I am unaware of?
m0n0wall is a rock solid networking solution.
I have been using it for years with no problems at all.

 
Pages: [1]
 
 
Powered by SMF 1.1.20 | SMF © 2013, Simple Machines