EFW Support

Support => General Support => Topic started by: Sheldmandu on Sunday 15 May 2011, 03:44:16 pm



Title: Cannot connect from GREEN to BLUE Network
Post by: Sheldmandu on Sunday 15 May 2011, 03:44:16 pm
Hi guys,

I've just setup EFW 2.4.1 (Previously was running 2.3) and decided to setup a wireless network as it should be (on a separate network, rather than directly on green/red/orange), but I'm finding that that I cannot connect from the GREEN network to anything on the BLUE network.  The BLUE network currently consists of a Cisco WRT320N Wireless Router (with the network cable connected from the EFW box to the LAN port of the WRT320N.  I also have a laptop connected wirelessly to the WRT320N.  The laptop on the blue network has no issues pinging hosts on the RED network or connecting to the internet.  The Firewall has the standard Inter-Zone Setup to allow ANY from GREEN to BLUE.  However, I cannot ping the WRT320N or the laptop from any host on the GREEN network.

If I log into EFW via SSH I have no issue pinging the WRT320N router, so it would appear there is an issue with the firewall.  I have looked at the output of iptables --list --verbose but havn't gone though all the rules as I'm not an iptables expert.

I'm pretty sure this is a bug, but wanted to see what others had to say before logging it in Mantis.


Title: Re: Cannot connect from GREEN to BLUE Network
Post by: susantadutta84 on Friday 10 June 2011, 03:42:13 pm


If you want to ping from green to blue zone then set the following rules in inter zone firewall.

1)source zone : green

Destination zone : Blue
protocol :ICMP

d. port :
ICMP/8
ICMP/30

 
2)source zone : blue
Destination zone : green
protocol :ICMP

d. port :
ICMP/8
ICMP/30