Re: DHCP woes
"Joe Acquisto-j4" <[email protected]> Tue, 20 Jun 2017 10:19:33 -0400
| Newsgroups | gmane.comp.security.ipcop.user |
|---|---|
| Message-ID | <5948F6B502000085000687D5@mail> |
>>> On 6/19/2017 at 5:28 PM, Dave Evans <[email protected]> wrote: > one thing to notice (because it's not very obviously documented) > in Firewall > Firewall Settings > you'll find by default > Green Open > Blue Open (I think - I don't have one to hand to test) > It's normal to set these to Half-Open once you've started setting up the > IPCOP, or to Closed - but I've never done that. > > this means > Open = all outbound traffic is allowed > Closed = all outbound traffic is refused, except that which is allowed > by specific rules > Half Open = as closed, except that all traffic is allowed to IPCOP to > the default services > > so for example if you set the interface to Half Open (which is a normal > thing to do) then in addition to any firewall rules you create, you will > also have > DNS allowed to IPCOP > DHCP allowed to IPCOP > NTP allowed to IPCOP > if the Proxy is on, then you'll have HTTP allowed to IPCOP & hence outward. > > now I'm not sure that the firewall rules in this situation cope properly > with DHCP traffic. I have seen it in other situations where DHCP > addresses leak from a dedicated DHCP server on Orange (Open) through to > Green, which didn't ought to happen but it did. Also to further confuse > things IPCOP was only providing DHCP on Blue. > The traffic must have been: > device on green starts DHCP exchange with a broadcast > traffic arrives at Green = half-open, IPCOP DHCP is off so this out to > be blocked, but arrives on Orange > dedicated DHCP server on Orange replies back to IPCOP > IPCOP relays the DHCP response back to the device on Green (obviously > the server on Green doing DHCP was busier at the time). Device now can't > connect as it has a Orange address. > (I know this is a messy scenario but it was to fix a particular problem > and I mention it in case it throws some light on Joe's issue) > > so in summary, you might want to set the Blue & Green interfaces to > Half-Open or to Closed (be careful to create some rules allowing you > access to IPCOP first or you might lock yourself out of IPCOP) > > if that fails follow Eric's advice and look in the files he mentions, > and see if you can document it doing the wrong things, then someone > might be able to fix it. > > Dave You know, in all this time, I don't recall ever seeing the "half open" thing. BLUE is half open. "now" or "has been" is left as an exercise for the reader . . . In any case, a quick look at (current) logs shows something that, to me, is very odd. 192.168.0.0 is GREEN. Yet in addition source GREEN for the IP shown below, I see BLUE as the source as well. There is no wireless (BLUE) interface on the host box for that IP. Than I know of. I built it. 09:49:08 BLUE REJECT wlan-1 TCP 192.168.0.242 5379 00:0c:29:aa.bb.cc 69.28.184.47 80(HTTP) 09:49:08 BLUE REJECT wlan-1 TCP 192.168.0.242 5378 00:0c:29:aa.bb.cc 69.28.184.47 80(HTTP) 09:49:07 BLUE REJECT wlan-1 UDP 192.168.0.242 63592 00:0c:29:aa.bb.cc 64.6.64.6 53(DOMAIN) 09:49:07 BLUE REJECT wlan-1 UDP 192.168.0.242 63592 00:0c:29:aa.bb.cc 192.168.0.250 53(DOMAIN) I need more coffee. joe a. ------------------------------------------------------------------------------ Check out the vibrant tech community on one of the world's most engaging tech sites, Slashdot.org! http://sdm.link/slashdot _______________________________________________ IPCop-user mailing list [email protected] Manage your subscription or unsubscribe https://lists.sourceforge.net/lists/listinfo/ipcop-user