Astaro User Bulletin Board
Go Back   Astaro User Bulletin Board > Astaro Gateway Products > Management, Networking, Logging and Reporting

Welcome to the Astaro User Bulletin Board.
If this is your first visit, be sure to check out the FAQ by clicking the link above. You may have to register before you can post: click the register link above to proceed. To start viewing messages, select the forum that you want to visit from the selection below.

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 02-01-2010, 02:35 PM
Junior Member
 
Join Date: Feb 2010
Posts: 3
Default 1 node denied access after inactivity

Hi all:

Interesting situation I'm facing. I have 8 devices on my network that access the internet; however this issue applies to only 1 of them, a Vista-based laptop. Whenever I cease all activity on this laptop (no typing or moving the mouse) for about 10 minutes or longer, then I'm denied the ability to access the internet altogether, regardless the application, for about 30 seconds to 3 minutes. Here are the specific details:

- All web-browsing is denied by the firewall; this is true via IE, FF, and Chrome.

- The ability to open a new internet stream via WMP, VLC Media Player, JLC Internet TV, etc is denied

- The firewall, according to the logs, will recognise the attempts to access the internet, however, the firewall views all of those attempts as a portscan and logs it as a portscan and naturally denies the request, during the 30 seconds - 3 minute window; after which, the access requests are granted again, and are logged as regular access requests and not as portscans.

- During the period of in which I am not using the laptop (not moving the mouse or typing), all logged in sites/applications will continue to remain logged in and all streams will continue; Gmail will still receive new emails/IMs during the inactivity, Skype will receive new IMs/calls, all music/tv streams will continue playing during the time in which I'm not typing or moving the mouse. However, once I move the mouse or start typing in a window, after about 10 minutes, then I lose all browser-based logins (Gmail disconnects, Skype disconnects, Meebo will disconnect, etc) however all music/tv streams will continue to stream. If I attempt to open a new browser and surf, I'm not permitted to any site that is NOT on my local LAN and I cannot start a new stream of any sort. But again, all existing streams will continue.

- During the 30 second to 3 minute window, I have full access to all sites ON the LAN, I can ping anything ON the LAN, visit any http site on the LAN (printer config page, for instance), access another local system via RDP, etc, however I cannot visit the WebAdmin page for Astaro from this one computer.

- Releasing and Renewing the IP DOES work properly, however, I'm still denied the ability to access the internet if it's still within the 30 second to 3 minute window. Astaro is my DHCP and DNS server. Again, all attempts to access the internet are viewed as portscans, even after an IP renewal.

- I setup the laptop with a static IP that differs from the one assigned by Astaro; I tried a static IP that was both within the DHCP scope and outside of the DHCP scope, but the problem continues.

None of the other nodes (printers, servers, workstations, etc) experience this issue, only this one system.

I have Astaro Security Gateway V7 Firmware 7.500.

Any help would be greatly appreciated!
Eneg

Last edited by Eneg; 02-01-2010 at 02:38 PM. Reason: Added FW version.
Reply With Quote
  #2 (permalink)  
Old 02-02-2010, 03:41 PM
Member
 
Join Date: Nov 2003
Posts: 45
Default

Same here with windows 7.
I had to make my internal network an exception in Network Security - Intrusion Prevention - Exceptions, skipping anti-portscan
Reply With Quote
  #3 (permalink)  
Old 02-02-2010, 05:10 PM
Junior Member
 
Join Date: Feb 2010
Posts: 3
Default

Thanks Moto for the info! This has been driving me crazy...I just made the change; I'll do some testing and reply back to let you know if it works for me as well.
Reply With Quote
  #4 (permalink)  
Old 02-03-2010, 02:13 AM
Junior Member
 
Join Date: Feb 2010
Posts: 3
Default

Moto - While it's only been today that I've been testing, I've not had the problem since I made that change so that's a great sign. Thanks again!
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT. The time now is 02:12 AM.

 

Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.


These pages are specifically maintained for the discussion of firewall issues within the Open Source community, and might already reflect new alpha/beta releases under development. Please refer to our product specifications for the functionality of the actual release. Discussions of new/enhanced functionality does not constitute a commitment of Astaro, to integrate this functionality into future releases. issues within the Open Source community, and might already reflect new alpha/beta releases under development. Please refer to our product specifications for the functionality of the actual release. Discussions of new/enhanced functionality does not constitute a commitment of Astaro, to integrate this functionality into future releases.