Jump to content
  • 0

KN-1210 Firewall Problem


Question

Posted (edited)

Hi there

I've got the Keenetic 4G with the latest firmware.

I have enabled firewall for Home segment. The default  rule is deny TCP/UDP.

DNS requests (UDP 53) are permitted. However this is not working (timeout on nslookup from clients).

If I disable the Deny UDP rule, DNS requests are working.

What is wrong?

 

Безымянный.png

Edited by stps2
  • Need more info 1

10 answers to this question

Recommended Posts

  • 0
Posted
44 minutes ago, stps2 said:

Self-test results was attached, but rejected by forum Administrator.

Accepted. Your post is hidden just in case it contains sensitive information. Still visible to @Le ecureuil 

  • 0
Posted

Also I've figured out that if I create an upper rule like 'Permit / UDP / Source IP: client IP / Source Port: Any / Destination IP: Any / Destination Port: Any", everything works.

So it is a bug that the rule mechanism does not take matter of destination IP address and port + Protocol, only Protocol (in case of UDP)

I've got an old deprecated model ZyXel / Keenetic Lite III with the same rule set, and it does not have this bug.

Can I contact the vendor support to fix this bug?

  • 0
Posted

У меня похожая проблема, но на KN-3810. Я хочу на сегмент сети запретить все UDP/TCP соединения и разрешить только определенные хосты (сайты). Сделал в настройках firewall нужного мне сегмента сети похожие настройки и если включаю DenyAll UDP, то у меня перестают работать DNS не смотря на то, что есть правило Allow UDP 53.

Есть ли какие то апдейты по этой теме? Почему оно не работает?

image.thumb.png.d3cca61300a247e1a92d6d2b0091a71d.png

 

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.
Note: Your post will require moderator approval before it will be visible.

Guest
Answer this question...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...