Geekzone: technology news, blogs, forums
Guest
Welcome Guest.
You haven't logged in yet. If you don't have an account you can register now.




89 posts

Master Geek


#242191 15-Oct-2018 16:12
Send private message

Hey all
I have a issue with my firewall on my USG

I have two vlans setup, Vlan 10 and 40
I have a PC on vlan 10 and a server on vlan 40

I have a rule setup to stop cross talk between the vlans, which works fine.
I then went to set a rule to allow ssh and http between the PC and the server.

First I found that I had to set a rule for both directions, PC->Server and then a reply back from Server -> PC
So I created a group with both the server and the PC's IP addresses and set a single rule from group to group
Rather than having two rules for each direction.
This worked fine.

I then went to add a port group to the rule to limit it to just ssh (22), and applied it to the firewall.
Broken.

If I allow any traffic it works fine, but the moment I add a port restrction it breaks.

Screenshots attached for reference.


Create new topic
1156 posts

Uber Geek

Lifetime subscriber

  #2108303 15-Oct-2018 16:35
Send private message

I think the problem is due to the fact that the source port is usually a random high port, as opposed to being the same as the destination port so the return traffic is being blocked. You want to allow related and established packets through your vlan in/local interface.

 

I use an edgerouter, and the below is how I have setup my vlan's:

 

Click to see full size

 

Click to see full size

 

Click to see full size

 

Click to see full size

 

Click to see full size

 

The default action on both GWN_IN and GWN_LOCAL is drop, so you'll see I allow specific things like DNS and DHCP. In addition I allow GWN to talk to anything apart from 192.168.0.0/16 so that it can access the internet, but not access anything in other vlans unless I've specified it above.

 

Not sure how that translates to USG but hopefully that'll help




89 posts

Master Geek


  #2108310 15-Oct-2018 16:49
Send private message

dfnt:

 

I think the problem is due to the fact that the source port is usually a random high port, as opposed to being the same as the destination port so the return traffic is being blocked. You want to allow related and established packets through your vlan in/local interface.

 

I use an edgerouter, and the below is how I have setup my vlan's:

 

Click to see full size

 

Click to see full size

 

Click to see full size

 

Click to see full size

 

Click to see full size

 

The default action on both GWN_IN and GWN_LOCAL is drop, so you'll see I allow specific things like DNS and DHCP. In addition I allow GWN to talk to anything apart from 192.168.0.0/16 so that it can access the internet, but not access anything in other vlans unless I've specified it above.

 

Not sure how that translates to USG but hopefully that'll help

 




I already have related and established enabled on the rule
Could it be getting confused as the fact its only one rule for both directions?
Trying to be clever and reduce the number of rules, but trying to do too much


 
 
 
 


436 posts

Ultimate Geek
Inactive user


  #2108324 15-Oct-2018 17:15
Send private message

With a "normal" firewall we usually only talk about stateful connections. The firewall usually maintains a state table, so any returning traffic is automatically allowed. So only a single rule is required. That whole new/related/established stuff is quite odd from a 100% firewall point of view. 

 

I'd wager its to do with your "Test IP" using both addresses in the source and destination parts of the rule. Then that weird ass statefulness check is screwing the return traffic up (due to it being on a port > 1024).

 

Make your address objects individual, that or get a real firewall :D

 

 

 

 


1156 posts

Uber Geek

Lifetime subscriber

  #2108421 15-Oct-2018 19:24
Send private message

Have you got any firewall rules on your main lan interface? I don't.

 

Also, you don't specify source ports, just leave that as ANY and the destination ports will be whatever you want

 

And put the established/related as its own rule at the very top as having it combined with your attempted rule isnt going to match any reply traffic

 

e.g.:

 

Click to see full size


Create new topic



Twitter and LinkedIn »



Follow us to receive Twitter updates when new discussions are posted in our forums:



Follow us to receive Twitter updates when news items and blogs are posted in our frontpage:



Follow us to receive Twitter updates when tech item prices are listed in our price comparison site:





News »

OPPO Find X2 Lite brings flagship features to mid-range 5G smartphone
Posted 29-May-2020 12:52


Sony introduces the digital camera ZV-1 for content creators
Posted 27-May-2020 12:47


Samsung Announces 2020 QLED TV Range
Posted 20-May-2020 16:29


D-Link A/NZ launches AI-Powered body temperature measuring system
Posted 20-May-2020 16:22


NortonLifeLock Online Banking Protection now available for New Zealand banks
Posted 20-May-2020 16:14


SD Express delivers new gigabyte speeds for SD memory cards
Posted 20-May-2020 15:00


D-Link A/NZ launches Nuclias cloud managed network solution hosted in Australia
Posted 11-May-2020 17:53


Logitech introduces new video streaming solution for home studios
Posted 11-May-2020 17:48


Next generation Volvo cars to be powered by Luminar LiDAR technology
Posted 7-May-2020 13:56


D-Link A/NZ launches Wi-Fi Certified EasyMesh system
Posted 7-May-2020 13:51


Spark teams up with Microsoft to bring Xbox All Access to New Zealand
Posted 7-May-2020 13:01


Microsoft plans to establish its first datacenter region in New Zealand
Posted 6-May-2020 11:35


Genesis School-gen has joined forces with Mind Lab Kids
Posted 1-May-2020 12:53


Malwarebytes expands into privacy with fast, frictionless VPN
Posted 30-Apr-2020 16:06


Kordia to donate TV airtime on Channel 200 to community groups
Posted 30-Apr-2020 16:00



Geekzone Live »

Try automatic live updates from Geekzone directly in your browser, without refreshing the page, with Geekzone Live now.


Support Geekzone »

Our community of supporters help make Geekzone possible. Click the button below to join them.

Support Geezone on PressPatron



Are you subscribed to our RSS feed? You can download the latest headlines and summaries from our stories directly to your computer or smartphone by using a feed reader.

Alternatively, you can receive a daily email with Geekzone updates.