News: This forum is now permanently frozen.
Pages: [1]
Topic: firewall on opt1  (Read 1155 times)
« on: September 12, 2014, 05:50:25 »
monowall_user *
Posts: 4

hi there
i have a problem with monowall. i activated opt1 and its running ok. i can connect to net. but i cant block all traffic and allow only one ip. the same settings work flawlessy on lan. but as soon as i block all traffic and allow only one ip on opt1 i cant connect to the ip. so is there some special configuration for opt1? i am a noob with networking so thanks for any help ! Smiley
« Reply #1 on: September 12, 2014, 23:45:01 »
Lee Sharp *****
Posts: 517

Rules are processed in order, so you have to allow the 1 IP first, then black all the rest.  (Actually, it default blocks, so you just need the Allow for one IP.)
« Reply #2 on: September 13, 2014, 07:03:34 »
monowall_user *
Posts: 4

hi thanks for your help
unfortunately it doesnt work even with only one rule, the one to pass this single ip.
« Reply #3 on: September 13, 2014, 07:27:06 »
Lee Sharp *****
Posts: 517

So, show us the rules on each interface.
« Reply #4 on: September 13, 2014, 07:39:38 »
monowall_user *
Posts: 4

this is the only active pass rule on opt1:

*    OPT1 net    *    194.107.107.204/31    *    opt1 ->https://ebanking.bawagpsk.com

i havnt changed anything on wan

its funny i get now a sort of connection with the site but after trying it again i just get an 403?
« Reply #5 on: September 18, 2014, 06:49:06 »
monowall_user *
Posts: 4

hi
could anybody please try out if its possible to connect to this site with only its ip active in the firewall?
194.107.107.204 https://ebanking.bawagpsk.com
do they redirect you to another ip?
thanks
« Reply #6 on: September 18, 2014, 16:51:53 »
Fred Grayson *****
Posts: 994

Is your destination of 194.107.107.204 entered as a 'single host or alias' or as a Network with a /31 netmask?

It should be 'single host or alias'.

--
Google is your friend and Bob's your uncle.
« Reply #7 on: September 19, 2014, 00:42:43 »
Lee Sharp *****
Posts: 517

Also, allow access to the firewall so DNS works.
 
Pages: [1]
 
 
Powered by SMF 1.1.20 | SMF © 2013, Simple Machines