Re: mono ip rules

Francisco Artes <[email protected]>
Newsgroups gmane.comp.security.firewalls.m0n0wall
Message-ID <[email protected]>
Depends on how the VPN server is setup.  Remember it too can have a set of ACLs and may not have been told to allow UDP 53.  Sometimes, depending on the VPN server, you have to tell it to allow DNS lookup and to what DNS server.  Not knowing what it is means I am speculating, but this could well be it.  

Now if you are seeing:
A block / Deny rule for "Source 10.1.0.4  port FOO destination 10.98.0.10 UDP 53 "
Then I would double check the subnet / CIDR that you setup for the UDP rule and ensure it is the entire /24.  You might have the CIDR wrong.  

Hope this helps.



On Jan 7, 2011, at 4:46 PM, Stefan Wiesinger wrote:

> hello.
> 
> i use mono v1.32 with the following setup. i've already searched the mailing-list archive but found no suitable answer.
> 
> [MONO 10.0.0.138] --PPTPinternetConnection-- [10.0.0.140 modem/internet]
> [MONO 10.98.0.254] --interface-- [10.98.0.10 DNS-Server (LAN)]
> [MONO 10.99.0.254] --interface-- [10.99.0.1 VPN-Server 10.1.0.1] --VPNconnection-over-the-internet-- [VPN-Client 10.1.0.4]
> 
> the vpn-clients are routed from the vpn-server to the rest of the networks.
> 
> now i tried to allow the vpn-client to access the dns-server. i defined a fw-rule in den ipv4-fw-rule for the interface on which the vpn-server is, to
> allow any traffic from any ip with destination UDP 53 and IP 10.98.0.10.
> when i look into the firewall-rules-log i see that the packets from the vpn-clients are blocked, but the packets from the vpn-server itself pass -->
> why? any ideas?
> 
> the routing must be ok, otherwise i wouldn't see the dropped packets in the monowall-webif.
> 
> hope anyone can help.
> 
> thank's in advance,
> stefan wiesinger
> 
> ---------------------------------------------------------------------
> To unsubscribe, e-mail: [email protected]
> For additional commands, e-mail: [email protected]
>
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.