DrayTek UK Users' Community Forum
Help, Advice and Solutions from DrayTek Users
SOLVED - 2927 Firewall not working
- chaser
- Topic Author
- Offline
- Junior Member
Less
More
- Posts: 17
- Thank you received: 0
12 Mar 2021 19:31 #98760
by chaser
SOLVED - 2927 Firewall not working was created by chaser
Hi,
I can't get the firewall to work on my Vigor 2927 (firmware v4.2.2). I have a fibre connection to WAN1 and and a VDSL connection to WAN2 (via a Vigor 2860 that is set up as a modem).
I am trying to block certain IP addresses from accessing my mail server, but they continue to get through, and I see them trying to connect in my mail server logs.
In the Firewall General Setup page:
In the Firewall Filter Setup page, Set#1 (Default Data Filter) is set up as follows:
Rule 2 is set up as follows:
212.70.149.71 is still getting through to my mail server, and I don't know why. If I try to use the Firewall Diagnose tool I get the following message:
The packet is not handled by firewall.(6)
I've also tried setting up a Filter Set 2, but that doesn't work either.
I also don't see anything appearing in the Syslog.
Any idea why this is not working?
I can't get the firewall to work on my Vigor 2927 (firmware v4.2.2). I have a fibre connection to WAN1 and and a VDSL connection to WAN2 (via a Vigor 2860 that is set up as a modem).
I am trying to block certain IP addresses from accessing my mail server, but they continue to get through, and I see them trying to connect in my mail server logs.
In the Firewall General Setup page:
In the Firewall Filter Setup page, Set#1 (Default Data Filter) is set up as follows:
Rule 2 is set up as follows:
212.70.149.71 is still getting through to my mail server, and I don't know why. If I try to use the Firewall Diagnose tool I get the following message:
The packet is not handled by firewall.(6)
I've also tried setting up a Filter Set 2, but that doesn't work either.
I also don't see anything appearing in the Syslog.
Any idea why this is not working?
Please Log in or Create an account to join the conversation.
- piste basher
- Offline
- Big Contributor
Less
More
- Posts: 1193
- Thank you received: 7
13 Mar 2021 10:16 #98762
by piste basher
Replied by piste basher on topic Re: 2927 Firewall not working
This is probably nothing to do with your problem but prompted to look at mine by your post I noticed that the 2927 no longer has a "Default Call Filter". First time I've seen this on a Draytek. Wonder why they have deemed it redundant after all these years?
What I would say is that the 2927 has some other features which don't work properly, e.g. in the Mesh Status page. It could just be that there is a problem, before you tear your hair out
What I would say is that the 2927 has some other features which don't work properly, e.g. in the Mesh Status page. It could just be that there is a problem, before you tear your hair out
Please Log in or Create an account to join the conversation.
- hornbyp
- Offline
- Big Contributor
Less
More
- Posts: 1323
- Thank you received: 0
14 Mar 2021 19:43 #98779
by hornbyp
I get the same message on my 2860 for that IP address. (It should definitely match an existing rule, given that it is a Bulgarian IP address:wink: - filtering by country, drastically reduces the amount of spam and other attacks that the Mail Server has to deal with)
I'm not sure I've ever got the 'Diagnose' function to do anything useful on the 2860.
I noticed the 'IPF flowtest' command on the 2860, but it's not documented in the manual. I tried copying and pasting the sample commands from
Page 804 of the Vigor 2926 manual
- but that also gave same message. (To be fair, it would take a fair while to understand what those commands actually do :wink: )
Are you sure Syslog is actually configured and receiving data?. (I have never had much success with the Web Gui interface - I much prefer the SyslogRD daemon.)
Replied by hornbyp on topic Re: 2927 Firewall not working
chaser wrote:
212.70.149.71 is still getting through to my mail server, and I don't know why. If I try to use the Firewall Diagnose tool I get the following message:
The packet is not handled by firewall.(6)
I get the same message on my 2860 for that IP address. (It should definitely match an existing rule, given that it is a Bulgarian IP address
I'm not sure I've ever got the 'Diagnose' function to do anything useful on the 2860.
I noticed the 'IPF flowtest' command on the 2860, but it's not documented in the manual. I tried copying and pasting the sample commands from
Are you sure Syslog is actually configured and receiving data?. (I have never had much success with the Web Gui interface - I much prefer the SyslogRD daemon.)
Please Log in or Create an account to join the conversation.
- hornbyp
- Offline
- Big Contributor
Less
More
- Posts: 1323
- Thank you received: 0
15 Mar 2021 14:54 #98786
by hornbyp
It turns out, I was doing it all wrong
As
@Hopkins35
pointed out, (in 2018!), the Destination Address needs to be the WAN address and not the LAN IP address of the target machine. :idea:
See:
https://forum.draytek.co.uk/viewtopic.php?f=14&t=22520&p=92960#p92960
Now I get a Firewall Hit on your "212.70.149.71"
Replied by hornbyp on topic Re: 2927 Firewall not working
chaser wrote:
If I try to use the Firewall Diagnose tool I get the following message:
The packet is not handled by firewall.(6)
and I wrote:
I'm not sure I've ever got the 'Diagnose' function to do anything useful on the 2860.
It turns out, I was doing it all wrong
As
See:
Now
Please Log in or Create an account to join the conversation.
- chaser
- Topic Author
- Offline
- Junior Member
Less
More
- Posts: 17
- Thank you received: 0
16 Mar 2021 12:46 #98795
by chaser
I'm using the WebGUI and I'm definitely getting lots of other messages flooding in!
Replied by chaser on topic Re: 2927 Firewall not working
hornbyp wrote:
Are you sure Syslog is actually configured and receiving data?. (I have never had much success with the Web Gui interface - I much prefer the SyslogRD daemon.)
I'm using the WebGUI and I'm definitely getting lots of other messages flooding in!
Ah. Thank you. Sounds like that's where I'm going wrong! I'll give that a try, and see if it works any better...hornbyp wrote:
It turns out, I was doing it all wrong
As@Hopkins35 pointed out, (in 2018!), the Destination Address needs to be the WANaddress and not the LAN IP address of the target machine. :idea:
See:https://forum.draytek.co.uk/viewtopic.php?f=14&t=22520&p=92960#p92960
NowI get a Firewall Hit on your "212.70.149.71"
Please Log in or Create an account to join the conversation.
- chaser
- Topic Author
- Offline
- Junior Member
Less
More
- Posts: 17
- Thank you received: 0
16 Mar 2021 13:46 #98797
by chaser
Replied by chaser on topic Re: 2927 Firewall not working
Using the WAN IP address instead of the LAP IP address has got the Diagnose tool working. However, it's reporting a PASS status from the default rule. It appears to be ignoring the rule that I set up in the Default Data Filter.
Edit: This is confusing. So, in filter set 1 (default data filter) I have:
Rule 1: xNetBios
Rule 2: Immediate block 212.70.149.71
Rule 3: Immediate block 212.70.149.71 (Duplicate of Rule 2)
If I run the Diagnose tool on 212.70.149.71, it blocks on Rule 2 (good!)
If I then swap rules 2 & 3 around and run the Diagnose tool on 212.70.149.71, it blocks on Rule 3 (good that it blocks, but bad that it seems to skip past rule 2).
If I then change rule 2 (the one that was originally rule 3) IP address to something different and run the Diagnose tool on that new IP address, it ultimately passes on default rule (bad)
If I then change rule 3 (the one that was originally rule 2) IP address to something different (same IP as the step above) and run the Diagnose tool on that new IP address, it blocks on Rule 3 (again good that it blocks, but bad that it seems to skip past rule 2).
I don't understand why only one of rules 2 & 3 seems to work? This issue actually extends beyond just rules 2 & 3. Ignoring rule 1, I can only get one of the other rules in set 1 to correctly block. All the others incorrectly pass! Even trying to set up new rules in Set 2 doesn't work.
Edit: This is confusing. So, in filter set 1 (default data filter) I have:
Rule 1: xNetBios
Rule 2: Immediate block 212.70.149.71
Rule 3: Immediate block 212.70.149.71 (Duplicate of Rule 2)
If I run the Diagnose tool on 212.70.149.71, it blocks on Rule 2 (good!)
If I then swap rules 2 & 3 around and run the Diagnose tool on 212.70.149.71, it blocks on Rule 3 (good that it blocks, but bad that it seems to skip past rule 2).
If I then change rule 2 (the one that was originally rule 3) IP address to something different and run the Diagnose tool on that new IP address, it ultimately passes on default rule (bad)
If I then change rule 3 (the one that was originally rule 2) IP address to something different (same IP as the step above) and run the Diagnose tool on that new IP address, it blocks on Rule 3 (again good that it blocks, but bad that it seems to skip past rule 2).
I don't understand why only one of rules 2 & 3 seems to work? This issue actually extends beyond just rules 2 & 3. Ignoring rule 1, I can only get one of the other rules in set 1 to correctly block. All the others incorrectly pass! Even trying to set up new rules in Set 2 doesn't work.
Please Log in or Create an account to join the conversation.
Moderators: Chris, Sami
Copyright © 2024 DrayTek