Astaro User Bulletin Board
Go Back   Astaro User Bulletin Board > Astaro Gateway Products > General Discussion

Welcome to the Astaro User Bulletin Board.
If this is your first visit, be sure to check out the FAQ by clicking the link above. You may have to register before you can post: click the register link above to proceed. To start viewing messages, select the forum that you want to visit from the selection below.

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 07-01-2009, 08:48 AM
Senior Member
 
Join Date: Oct 2008
Posts: 133
Default cant use ftp

why in the blank does asg block so much when a lot of stuff is SAFE? This really ticks me off. In no way should it block me from using ftp. How stupid!! I don't think i should have to set rules for every little damn thing. then I'd end up with hundreds or thousands of rules.

PF is blocking me from using ftp so i can connect to ftp servers out there.
Reply With Quote
  #2 (permalink)  
Old 07-01-2009, 08:54 AM
Wizard
 
Join Date: Jul 2008
Posts: 1,408
Default

Quote:
Originally Posted by buggs1a View Post
why in the blank does asg block so much when a lot of stuff is SAFE? This really ticks me off. In no way should it block me from using ftp. How stupid!! I don't think i should have to set rules for every little damn thing. then I'd end up with hundreds or thousands of rules.

PF is blocking me from using ftp so i can connect to ftp servers out there.
Can u please check/send log
screen shots


Thanks
Reply With Quote
  #3 (permalink)  
Old 07-01-2009, 09:16 AM
Senior Member
 
Join Date: Oct 2008
Posts: 133
Default

It's the 84 ip one. that is the ftp being blocked. I try to connect to ftp.livedrive.com and it is blocked. 84.45.62.203

2009:07:01-00:43:44 joe ulogd[3251]: id="2001" severity="info" sys="SecureNet" sub="packetfilter" name="Packet dropped" action="drop" fwrule="60002" seq="0" initf="eth1" outitf="eth1" dstmac="00:40:f4:58:9c:a7" srcmac="00:01:02:71:e8:f2" srcip="192.168.1.254" dstip="84.45.62.203" proto="6" length="64" tos="0x00" prec="0x00" ttl="63" srcport="49398" dstport="21" tcpflags="SYN"
2009:07:01-00:43:45 joe ulogd[3251]: id="2001" severity="info" sys="SecureNet" sub="packetfilter" name="Packet dropped" action="drop" fwrule="60002" seq="0" initf="eth1" outitf="eth1" dstmac="00:40:f4:58:9c:a7" srcmac="00:01:02:71:e8:f2" srcip="192.168.1.254" dstip="84.45.62.203" proto="6" length="64" tos="0x00" prec="0x00" ttl="63" srcport="49398" dstport="21" tcpflags="SYN"
2009:07:01-00:43:46 joe ulogd[3251]: id="2001" severity="info" sys="SecureNet" sub="packetfilter" name="Packet dropped" action="drop" fwrule="60002" seq="0" initf="eth1" outitf="eth1" dstmac="00:40:f4:58:9c:a7" srcmac="00:01:02:71:e8:f2" srcip="192.168.1.254" dstip="84.45.62.203" proto="6" length="64" tos="0x00" prec="0x00" ttl="63" srcport="49398" dstport="21" tcpflags="SYN"
2009:07:01-00:43:47 joe ulogd[3251]: id="2001" severity="info" sys="SecureNet" sub="packetfilter" name="Packet dropped" action="drop" fwrule="60002" seq="0" initf="eth1" outitf="eth1" dstmac="00:40:f4:58:9c:a7" srcmac="00:01:02:71:e8:f2" srcip="192.168.1.254" dstip="84.45.62.203" proto="6" length="48" tos="0x00" prec="0x00" ttl="63" srcport="49398" dstport="21" tcpflags="SYN"
2009:07:01-00:43:48 joe ulogd[3251]: id="2001" severity="info" sys="SecureNet" sub="packetfilter" name="Packet dropped" action="drop" fwrule="60002" seq="0" initf="eth1" outitf="eth1" dstmac="00:40:f4:58:9c:a7" srcmac="00:01:02:71:e8:f2" srcip="192.168.1.254" dstip="84.45.62.203" proto="6" length="48" tos="0x00" prec="0x00" ttl="63" srcport="49398" dstport="21" tcpflags="SYN"
2009:07:01-00:43:49 joe ulogd[3251]: id="2001" severity="info" sys="SecureNet" sub="packetfilter" name="Packet dropped" action="drop" fwrule="60002" seq="0" initf="eth1" outitf="eth1" dstmac="00:40:f4:58:9c:a7" srcmac="00:01:02:71:e8:f2" srcip="192.168.1.254" dstip="84.45.62.203" proto="6" length="48" tos="0x00" prec="0x00" ttl="63" srcport="49398" dstport="21" tcpflags="SYN"
2009:07:01-00:43:51 joe ulogd[3251]: id="2001" severity="info" sys="SecureNet" sub="packetfilter" name="Packet dropped" action="drop" fwrule="60002" seq="0" initf="eth1" outitf="eth1" dstmac="00:40:f4:58:9c:a7" srcmac="00:01:02:71:e8:f2" srcip="192.168.1.254" dstip="84.45.62.203" proto="6" length="48" tos="0x00" prec="0x00" ttl="63" srcport="49398" dstport="21" tcpflags="SYN"
2009:07:01-00:43:55 joe ulogd[3251]: id="2001" severity="info" sys="SecureNet" sub="packetfilter" name="Packet dropped" action="drop" fwrule="60002" seq="0" initf="eth1" outitf="eth1" dstmac="00:40:f4:58:9c:a7" srcmac="00:01:02:71:e8:f2" srcip="192.168.1.254" dstip="84.45.62.203" proto="6" length="48" tos="0x00" prec="0x00" ttl="63" srcport="49398" dstport="21" tcpflags="SYN"
2009:07:01-00:44:03 joe ulogd[3251]: id="2001" severity="info" sys="SecureNet" sub="packetfilter" name="Packet dropped" action="drop" fwrule="60002" seq="0" initf="eth1" outitf="eth1" dstmac="00:40:f4:58:9c:a7" srcmac="00:01:02:71:e8:f2" srcip="192.168.1.254" dstip="84.45.62.203" proto="6" length="48" tos="0x00" prec="0x00" ttl="63" srcport="49398" dstport="21" tcpflags="SYN"
2009:07:01-00:44:16 joe ulogd[3251]: id="2001" severity="info" sys="SecureNet" sub="packetfilter" name="Packet dropped" action="drop" fwrule="60001" seq="0" initf="eth0" outitf="eth0" dstmac="00:01:02:71:e8:f2" srcmac="00:00:00:00:00:00" srcip="73.98.106.1" dstip="224.0.0.1" proto="2" length="28" tos="0x00" prec="0xc0" ttl="1"
2009:07:01-00:44:20 joe ulogd[3251]: id="2001" severity="info" sys="SecureNet" sub="packetfilter" name="Packet dropped" action="drop" fwrule="60002" seq="0" initf="eth1" outitf="eth1" dstmac="00:40:f4:58:9c:a7" srcmac="00:01:02:71:e8:f2" srcip="192.168.1.254" dstip="84.45.62.203" proto="6" length="64" tos="0x00" prec="0x00" ttl="63" srcport="49411" dstport="21" tcpflags="SYN"
2009:07:01-00:44:21 joe ulogd[3251]: id="2001" severity="info" sys="SecureNet" sub="packetfilter" name="Packet dropped" action="drop" fwrule="60002" seq="0" initf="eth1" outitf="eth1" dstmac="00:40:f4:58:9c:a7" srcmac="00:01:02:71:e8:f2" srcip="192.168.1.254" dstip="84.45.62.203" proto="6" length="64" tos="0x00" prec="0x00" ttl="63" srcport="49411" dstport="21" tcpflags="SYN"
2009:07:01-00:44:22 joe ulogd[3251]: id="2001" severity="info" sys="SecureNet" sub="packetfilter" name="Packet dropped" action="drop" fwrule="60002" seq="0" initf="eth1" outitf="eth1" dstmac="00:40:f4:58:9c:a7" srcmac="00:01:02:71:e8:f2" srcip="192.168.1.254" dstip="84.45.62.203" proto="6" length="64" tos="0x00" prec="0x00" ttl="63" srcport="49411" dstport="21" tcpflags="SYN"
2009:07:01-00:44:23 joe ulogd[3251]: id="2001" severity="info" sys="SecureNet" sub="packetfilter" name="Packet dropped" action="drop" fwrule="60002" seq="0" initf="eth1" outitf="eth1" dstmac="00:40:f4:58:9c:a7" srcmac="00:01:02:71:e8:f2" srcip="192.168.1.254" dstip="84.45.62.203" proto="6" length="48" tos="0x00" prec="0x00" ttl="63" srcport="49411" dstport="21" tcpflags="SYN"
2009:07:01-00:44:24 joe ulogd[3251]: id="2001" severity="info" sys="SecureNet" sub="packetfilter" name="Packet dropped" action="drop" fwrule="60002" seq="0" initf="eth1" outitf="eth1" dstmac="00:40:f4:58:9c:a7" srcmac="00:01:02:71:e8:f2" srcip="192.168.1.254" dstip="84.45.62.203" proto="6" length="48" tos="0x00" prec="0x00" ttl="63" srcport="49411" dstport="21" tcpflags="SYN"
2009:07:01-00:44:25 joe ulogd[3251]: id="2001" severity="info" sys="SecureNet" sub="packetfilter" name="Packet dropped" action="drop" fwrule="60002" seq="0" initf="eth1" outitf="eth1" dstmac="00:40:f4:58:9c:a7" srcmac="00:01:02:71:e8:f2" srcip="192.168.1.254" dstip="84.45.62.203" proto="6" length="48" tos="0x00" prec="0x00" ttl="63" srcport="49411" dstport="21" tcpflags="SYN"
2009:07:01-00:44:27 joe ulogd[3251]: id="2001" severity="info" sys="SecureNet" sub="packetfilter" name="Packet dropped" action="drop" fwrule="60002" seq="0" initf="eth1" outitf="eth1" dstmac="00:40:f4:58:9c:a7" srcmac="00:01:02:71:e8:f2" srcip="192.168.1.254" dstip="84.45.62.203" proto="6" length="48" tos="0x00" prec="0x00" ttl="63" srcport="49411" dstport="21" tcpflags="SYN"
2009:07:01-00:44:31 joe ulogd[3251]: id="2001" severity="info" sys="SecureNet" sub="packetfilter" name="Packet dropped" action="drop" fwrule="60002" seq="0" initf="eth1" outitf="eth1" dstmac="00:40:f4:58:9c:a7" srcmac="00:01:02:71:e8:f2" srcip="192.168.1.254" dstip="84.45.62.203" proto="6" length="48" tos="0x00" prec="0x00" ttl="63" srcport="49411" dstport="21" tcpflags="SYN"
2009:07:01-00:44:47 joe ulogd[3251]: id="2001" severity="info" sys="SecureNet" sub="packetfilter" name="Packet dropped" action="drop" fwrule="60002" seq="0" initf="eth1" outitf="eth1" dstmac="00:40:f4:58:9c:a7" srcmac="00:01:02:71:e8:f2" srcip="192.168.1.254" dstip="17.151.16.20" proto="17" length="76" tos="0x00" prec="0x00" ttl="63" srcport="123" dstport="123"
2009:07:01-00:45:16 joe ulogd[3251]: id="2001" severity="info" sys="SecureNet" sub="packetfilter" name="Packet dropped" action="drop" fwrule="60001" seq="0" initf="eth0" outitf="eth0" dstmac="00:01:02:71:e8:f2" srcmac="00:00:00:00:00:00" srcip="73.98.106.1" dstip="224.0.0.1" proto="2" length="28" tos="0x00" prec="0xc0" ttl="1"
2009:07:01-00:45:21 joe ulogd[3251]: id="2001" severity="info" sys="SecureNet" sub="packetfilter" name="Packet dropped" action="drop" fwrule="60002" seq="0" initf="eth1" outitf="eth1" dstmac="00:40:f4:58:9c:a7" srcmac="00:01:02:71:e8:f2" srcip="192.168.1.254" dstip="84.45.62.203" proto="6" length="64" tos="0x00" prec="0x00" ttl="63" srcport="49417" dstport="21" tcpflags="SYN"
2009:07:01-00:45:22 joe ulogd[3251]: id="2001" severity="info" sys="SecureNet" sub="packetfilter" name="Packet dropped" action="drop" fwrule="60002" seq="0" initf="eth1" outitf="eth1" dstmac="00:40:f4:58:9c:a7" srcmac="00:01:02:71:e8:f2" srcip="192.168.1.254" dstip="84.45.62.203" proto="6" length="64" tos="0x00" prec="0x00" ttl="63" srcport="49417" dstport="21" tcpflags="SYN"
2009:07:01-00:45:23 joe ulogd[3251]: id="2001" severity="info" sys="SecureNet" sub="packetfilter" name="Packet dropped" action="drop" fwrule="60002" seq="0" initf="eth1" outitf="eth1" dstmac="00:40:f4:58:9c:a7" srcmac="00:01:02:71:e8:f2" srcip="192.168.1.254" dstip="84.45.62.203" proto="6" length="64" tos="0x00" prec="0x00" ttl="63" srcport="49417" dstport="21" tcpflags="SYN"
2009:07:01-00:45:24 joe ulogd[3251]: id="2001" severity="info" sys="SecureNet" sub="packetfilter" name="Packet dropped" action="drop" fwrule="60002" seq="0" initf="eth1" outitf="eth1" dstmac="00:40:f4:58:9c:a7" srcmac="00:01:02:71:e8:f2" srcip="192.168.1.254" dstip="84.45.62.203" proto="6" length="48" tos="0x00" prec="0x00" ttl="63" srcport="49417" dstport="21" tcpflags="SYN"
2009:07:01-00:45:25 joe ulogd[3251]: id="2001" severity="info" sys="SecureNet" sub="packetfilter" name="Packet dropped" action="drop" fwrule="60002" seq="0" initf="eth1" outitf="eth1" dstmac="00:40:f4:58:9c:a7" srcmac="00:01:02:71:e8:f2" srcip="192.168.1.254" dstip="84.45.62.203" proto="6" length="48" tos="0x00" prec="0x00" ttl="63" srcport="49417" dstport="21" tcpflags="SYN"
2009:07:01-00:45:26 joe ulogd[3251]: id="2001" severity="info" sys="SecureNet" sub="packetfilter" name="Packet dropped" action="drop" fwru
Reply With Quote
  #4 (permalink)  
Old 07-02-2009, 07:18 PM
AngeloC's Avatar
Ninja
 
Join Date: May 2003
Posts: 291
Default

hi buggs,

Astaro stops everything by default, which is intended vs having to read documentation and/or remove configuration in order to close holes opened at the factory by a "default" policy. Since our policy is to log and drop everything, this is expected here.

if you'd like a global outgoing allow policy so you dont have to open "outgoing" ports, just do

source: internal network destination:any service: any action: allow in the packetfilter and place it at the top.

Anytime you see the rule number 60,000+ its the default rule doing the drop (meaning the traffic has passed through every rule on the table and ended up not being matched, so it falls under the default behaviour). This default rule is not visible on the rules list.
__________________
Angelo Comazzetto
Astaro AG
--------------------------------------------------------
Visit the KB for documentation and help (www.astaro.com/kb)
Astaro is FULLY free for home use, including all subscriptions. Download it from http://my.astaro.com
Reply With Quote
  #5 (permalink)  
Old 07-02-2009, 07:21 PM
Super Moderator
 
Join Date: Feb 2009
Location: In a galaxy far far away
Posts: 762
Default

Quote:
Originally Posted by AngeloC View Post
Anytime you see the rule number 60,000+ its the default rule doing the drop (meaning the traffic has passed through every rule on the table and ended up not being matched, so it falls under the default behaviour). This default rule is not visible on the rules list.
Thanks for that AngeloC, It will help a lot in future troubleshooting
__________________

Running Astaro ASG virtual appliance | Home power user 100 IP license
Intel Dual Core 2.4GHz (800MHz) | 4GB (2 x 2GB) PC2-6400 800Mhz 5-5-5-18 | WD 160GB |3 x Intel Pro/1000
Reply With Quote
  #6 (permalink)  
Old 07-03-2009, 01:37 AM
Senior Member
 
Join Date: Oct 2008
Posts: 133
Default

Yes totally! Thank you so much. I do agree with being more secure making us opt in and allow stuff. I am used to other routers and appliances that by default allow lan to wan everything like you suggested I could make a rule for. I prefer that since I'm not needing that explicit security.
Reply With Quote
  #7 (permalink)  
Old 07-05-2009, 01:50 AM
Simon Shaw's Avatar
Aussie moderator.
 
Join Date: Jun 2001
Location: Perth, Western Australia
Posts: 2,628
Default

buggs1a, Astaro is a higher end security product.

It should not really be implemented unless you have a clear understanding of how to use it as you could compromise the security of your network.
(Same goes for any firewall setup to be honest).

If you read the FAQs and manuals, or search these forums you should get answers to just about any setup question. (Or even try the online help).

If you are just protecting a small home LAN, maybe just use your routers firewall.
__________________
Simon Shaw
Systems Manager
Micromine PL

Intel 2.66GHz Quad Core, 4GB (2 x 2GB) PC-6400 800Mhz 4-4-4-12, WD 300GB 10K RPM VelociRaptor, Intel Pro/1000 Quad Port PCI-X
http://www.sputcorp.com/
Reply With Quote
  #8 (permalink)  
Old 07-05-2009, 12:31 PM
AngeloC's Avatar
Ninja
 
Join Date: May 2003
Posts: 291
Default

Anytime. Happy to help out. Enjoy using Astaro, it can do a lot for you. If you get stuck, let us know.
__________________
Angelo Comazzetto
Astaro AG
--------------------------------------------------------
Visit the KB for documentation and help (www.astaro.com/kb)
Astaro is FULLY free for home use, including all subscriptions. Download it from http://my.astaro.com
Reply With Quote
  #9 (permalink)  
Old 07-06-2009, 06:09 PM
Senior Member
 
Join Date: Oct 2008
Posts: 133
Default

Simon, I know all that except it's hard to find how tos and examples. That is not available for most anything I wanna do in ways I can understand which means do this step 1 then step 2 etc.

The problem with using s home router for a home network is thst it offers no security like the better ones do. No AV and bandwidth counting etc.
Plus i like to learn.
Reply With Quote
  #10 (permalink)  
Old 07-06-2009, 07:06 PM
BAlfson's Avatar
Moderator
 
Join Date: Mar 2007
Location: Oklahoma City
Posts: 4,954
Default

The more-secure way to use FTP is by enabling the FTP proxy in the Astaro.

Go to 'Web Security >> FTP'
On the 'Global' tab,
- [Enable] the proxy,
- choose the "Transparent" mode and
- click the folder to drag 'Internal (Network)' into 'Allowed networks'.
-Click [Apply].

On the 'Advanced' tab, in the 'FTP Servers' section,
-click on the folder and
-drag 'Any' into the box for 'Allowed servers'.
-Click [Apply].

Now you should have to trouble with FTP.

When you turn on the FTP Proxy, the Astaro automatically creates the packet filter rules that you need for FTP. The same thing is done in many places in the Astaro. I believe each of the proxies manages its own packet filter rules.

There are some places where you can choose to create your own packet filter rules. This includes VPNs and NAT rules. That requires you to unclick a box for 'Automatic packet filter rules' that you find there.

Cheers - Bob
__________________
ACE V7 - Astaro Preferred Partner since V3
Addicted to my iPhone!
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT. The time now is 03:47 PM.

 

Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.


These pages are specifically maintained for the discussion of firewall issues within the Open Source community, and might already reflect new alpha/beta releases under development. Please refer to our product specifications for the functionality of the actual release. Discussions of new/enhanced functionality does not constitute a commitment of Astaro, to integrate this functionality into future releases. issues within the Open Source community, and might already reflect new alpha/beta releases under development. Please refer to our product specifications for the functionality of the actual release. Discussions of new/enhanced functionality does not constitute a commitment of Astaro, to integrate this functionality into future releases.