News: This forum is now permanently frozen.
Pages: [1]
Topic: Configuring M0n0wall to pass all traffic from one interface to the other  (Read 872 times)
« on: April 27, 2014, 05:53:12 »
PiGal777 *
Posts: 3

Hi,
Please find attach drawing of a part of virtual (VMWare) network I am building.  Both devices are m0n0wall. I have configured both of them to pass any protocol from any source to any destination and any port on both LAN & WAN interfaces (Pass * * * * *).
Top one (M1) has a routing defined as follows:
192.168.0.16/30 gw 192.168.0.18
192.168.250.0/29 gw 192.168.250.2
Bottom one (M2) has a routing defined as follows:
192.168.0.24/30 gw 192.168.0.26
192.168.250.0/29 gw 192.168.250.1
Both of them have NAT disabled as well as spoof checking on bridge as well as block private networks on WAN interface.
Both have bypass  firewall rules for traffic on the same interface enabled.
All IPs are static.

When I try to use diagnostic tools from M1 and ping 192.168.0.25 echoreply is blocked on WAN interface of M1. There is no issue with pinging 192.168.250.2 from M1. When I do a trace route from M1 for 192.168.0.25 the answer is positive - it finds the path...

What am I missing?





* Part.jpg (21.39 KB, 462x296 - viewed 161 times.)
« Last Edit: April 27, 2014, 06:33:32 by PiGal777 »
« Reply #1 on: April 28, 2014, 00:43:23 »
Lee Sharp *****
Posts: 517

If you have NAT running on both of those routers you have to either account for it or turn it off.
« Reply #2 on: April 28, 2014, 12:19:54 »
PiGal777 *
Posts: 3

If you have NAT running on both of those routers you have to either account for it or turn it off.

As I stated in my post NAT is disabled:

Both of them have NAT disabled as well...

I just want to use m0n0wall as simple router without NAT, firewall or anything fancy. Routing between different networks...

I can replicate this scenario on lubuntu and after ufw disable (disabling firewall) it works like a champ. Moreover in m0n0 scenario ICMP traffic is evidently blocked by M1 firewall as exact entry from M1 firewall log is :
X   13:41:50.268872    WAN    192.168.250.2    192.168.250.1, type echoreply/0    ICMP  
« Last Edit: April 28, 2014, 14:06:17 by PiGal777 »
« Reply #3 on: April 28, 2014, 17:03:43 »
Lee Sharp *****
Posts: 517

With NAT off, and allow all firewall rules, and the private IP blocking disabled, you have a simple router only.  If it is not working at this point, look at your static routes...

Also, I see VMnet.  There are occasionally some issues with m0n0wall on VMware, and simply not passing some traffic.  Others would need to chime in on this...  To test it, just stick m0n0wall on an old desktop, and see if you have the same issues.
 
Pages: [1]
 
 
Powered by SMF 1.1.20 | SMF © 2013, Simple Machines