Jump to content
  • 0

KN-1210 Firewall Problem



Hi there

I've got the Keenetic 4G with the latest firmware.

I have enabled firewall for Home segment. The default  rule is deny TCP/UDP.

DNS requests (UDP 53) are permitted. However this is not working (timeout on nslookup from clients).

If I disable the Deny UDP rule, DNS requests are working.

What is wrong?



Edited by stps2
  • Need more info 1
Link to comment
Share on other sites

10 answers to this question

Recommended Posts

  • 0

Also I've figured out that if I create an upper rule like 'Permit / UDP / Source IP: client IP / Source Port: Any / Destination IP: Any / Destination Port: Any", everything works.

So it is a bug that the rule mechanism does not take matter of destination IP address and port + Protocol, only Protocol (in case of UDP)

I've got an old deprecated model ZyXel / Keenetic Lite III with the same rule set, and it does not have this bug.

Can I contact the vendor support to fix this bug?

Link to comment
Share on other sites

  • 0

У меня похожая проблема, но на KN-3810. Я хочу на сегмент сети запретить все UDP/TCP соединения и разрешить только определенные хосты (сайты). Сделал в настройках firewall нужного мне сегмента сети похожие настройки и если включаю DenyAll UDP, то у меня перестают работать DNS не смотря на то, что есть правило Allow UDP 53.

Есть ли какие то апдейты по этой теме? Почему оно не работает?



Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.
Note: Your post will require moderator approval before it will be visible.

Answer this question...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Create New...