Re: FireHOL and miniupnpd

Ignacio Benedetti <[email protected]> Sun, 6 Sep 2015 14:34:11 -0300
Newsgroups gmane.comp.security.firewalls.firehol.user
Message-ID <CAECK1csMHSoo2vnTxRtW=VfgDd4zub2Z5Jg9i3OFC+8VamzFvQ@mail.gmail.com>
On Sat, Aug 8, 2015 at 6:54 AM, Phil Whineray <[email protected]> wrote:

> Hi Ignacio
>

Hello Phil!


> If it works with policy accept, can you try adding into "nolan" the
> "server multicast accept" and report the logs accordingly?
>

Thanks, that was the solution!

Coming back to miniupnpd: I guess that is receiving my "open the port"
request but does not really opens the port.

I added a custom service to FireHOL: natpmp and accept him in "lan" context
to allow the udp request to 5351 reach the miniupnpd daemon.

I see this attributes in the config file of miniupnpd:
# Chain names for netfilter (not used for pf or ipf).
# default is MINIUPNPD for both
#upnp_forward_chain=forwardUPnP
#upnp_nat_chain=UPnP

How can I know what is the name assigned by FireHOL for these chains?
Will this be the solution?

Thanks!

Current FHOL config: http://pastebin.com/ykbzbhuJ
_______________________________________________
Firehol-support mailing list
[email protected]
http://lists.firehol.org/mailman/listinfo/firehol-support