stps2 Posted October 11, 2022 Posted October 11, 2022 (edited) Hi there I've got the Keenetic 4G with the latest firmware. I have enabled firewall for Home segment. The default rule is deny TCP/UDP. DNS requests (UDP 53) are permitted. However this is not working (timeout on nslookup from clients). If I disable the Deny UDP rule, DNS requests are working. What is wrong? Edited October 11, 2022 by stps2 1 Quote
0 Le ecureuil Posted October 11, 2022 Posted October 11, 2022 Please provide self-test for investigation. Quote
0 stps2 Posted October 11, 2022 Author Posted October 11, 2022 Self-test results was attached, but rejected by forum Administrator. Quote
0 stps2 Posted October 11, 2022 Author Posted October 11, 2022 Is there an alternative way to provide self-test results? Quote
0 admin Posted October 11, 2022 Posted October 11, 2022 44 minutes ago, stps2 said: Self-test results was attached, but rejected by forum Administrator. Accepted. Your post is hidden just in case it contains sensitive information. Still visible to @Le ecureuil Quote
0 stps2 Posted October 11, 2022 Author Posted October 11, 2022 Also I've figured out that if I create an upper rule like 'Permit / UDP / Source IP: client IP / Source Port: Any / Destination IP: Any / Destination Port: Any", everything works. So it is a bug that the rule mechanism does not take matter of destination IP address and port + Protocol, only Protocol (in case of UDP) I've got an old deprecated model ZyXel / Keenetic Lite III with the same rule set, and it does not have this bug. Can I contact the vendor support to fix this bug? Quote
0 iCurious Posted September 17, 2023 Posted September 17, 2023 У меня похожая проблема, но на KN-3810. Я хочу на сегмент сети запретить все UDP/TCP соединения и разрешить только определенные хосты (сайты). Сделал в настройках firewall нужного мне сегмента сети похожие настройки и если включаю DenyAll UDP, то у меня перестают работать DNS не смотря на то, что есть правило Allow UDP 53. Есть ли какие то апдейты по этой теме? Почему оно не работает? Quote
Question
stps2
Hi there
I've got the Keenetic 4G with the latest firmware.
I have enabled firewall for Home segment. The default rule is deny TCP/UDP.
DNS requests (UDP 53) are permitted. However this is not working (timeout on nslookup from clients).
If I disable the Deny UDP rule, DNS requests are working.
What is wrong?
10 answers to this question
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.
Note: Your post will require moderator approval before it will be visible.