News: This forum is now permanently frozen.
Pages: [1]
Topic: How to Remove Built-In Firewall Rule  (Read 946 times)
« on: September 14, 2014, 19:05:45 »
0xAether *
Posts: 5

The highlighted rule in the attached image is causing me trouble. How do I remove it?


* Capture.PNG (41.27 KB, 683x423 - viewed 2107 times.)
« Reply #1 on: September 14, 2014, 19:59:17 »
Fred Grayson *****
Posts: 994

Look on Interfaces: WAN page. Is there a check mark in the box next to "Block private networks"? If so, remove it and press the Save button.

--
Google is your friend and Bob's your uncle.
« Reply #2 on: September 14, 2014, 20:16:38 »
0xAether *
Posts: 5

Look on Interfaces: WAN page. Is there a check mark in the box next to "Block private networks"? If so, remove it and press the Save button.

It was checked, I unchecked it but the problem is still happening.

The IP address of this firewall is 10.1.0.1/16 Any machine on that subnet can get online. Any machine from any other subnet is being blocked by this rule.


* Capture.PNG (20.07 KB, 586x306 - viewed 198 times.)

* Capture1.PNG (28.52 KB, 915x134 - viewed 235 times.)
« Reply #3 on: September 14, 2014, 20:37:26 »
Fred Grayson *****
Posts: 994

We would have to know more about your configuration, especially about any other interfaces, as those rejected packets are coming from another network.

--
Google is your friend and Bob's your uncle.
« Reply #4 on: September 14, 2014, 20:47:24 »
0xAether *
Posts: 5

We would have to know more about your configuration, especially about any other interfaces, as those rejected packets are coming from another network.

In a nutshell, I have a switch that is doing all my layer 3 routing. Anything that isn't on any of my VLANs is sent to my m0n0wall. My m0n0wall is 10.1.0.1/16 and I have a few other networks. In this case, I was trying to get to Google from 10.8.0.1/16. My switch was sending the traffic to the default route, which is to the m0n0wall.

I know for a face that the rule I have highlighted is the culprit as I can get online from any machine that's on the 10.1.0.0/16 network (the same network that the m0n0wall is on)

Any specific config files you need, I will certainly provide them. I want to get this into production ASAP.
« Reply #5 on: September 16, 2014, 03:13:18 »
0xAether *
Posts: 5

Does anyone have any further ideas?
« Reply #6 on: September 19, 2014, 00:41:37 »
Lee Sharp *****
Posts: 517

So this is a dupe of the question I just answered...  Not really feeling like retyping that, so read it and add that m0n0wall neeeds some statinc routes to your switch.
 
Pages: [1]
 
 
Powered by SMF 1.1.20 | SMF © 2013, Simple Machines