[ previous ] [ next ] [ threads ]
 
 From:  Dirk Kreyenberg <dirk at abstauber dot net>
 To:  m0n0wall at lists dot m0n0 dot ch
 Subject:  Firewall Issues with subnets
 Date:  Thu, 08 Jan 2004 10:55:28 +0100
Hi there,

I'm encountering the problem that m0n0wall keeps ignoring me and my
commands (I'm running pb23r570 on a Soekris net4801 btw.) and I'm a
little confused about that. So it would be very nice if anyone could
help me out. 

My Network looks like the following:

WAN (PPPoE)---m0n0wall---DMZ 192.168.150.0/24--
--LANs:192.168.201.0/24 - 205.0/24

The LANs are connected to the DMZ via a multiport Router, its interface
to the DMZ has the IP 192.168.150.2.
With the standard FW-rules, only the DMZ is allowed to access the
internet (proto: *; source: LAN net; Port *; Dest *; Port *) 
So the m0n0wall box is blocking access requests from 201 to 205, while
everthing from net 150 can acces the WAN.
I now added following passing rule:
Proto: *; source: 192.168.201.0/24; Port: *; Dest *; Port *
Unfortunately the Firewall logs are then showing me, that all traffic
from 192.168.201.0 is still beeing blocked. 
This also happens if I try that with the other segments.

I have absolutely no clue why this is happening, so please can anyone
help?

Thanks,
Dirk