Astaro User Bulletin Board
Go Back   Astaro User Bulletin Board > Astaro Gateway Products > Network Security: Firewall, NAT, QoS, IPS and more

Welcome to the Astaro User Bulletin Board.
If this is your first visit, be sure to check out the FAQ by clicking the link above. You may have to register before you can post: click the register link above to proceed. To start viewing messages, select the forum that you want to visit from the selection below.

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 01-23-2004, 06:23 PM
Member
 
Join Date: Sep 2003
Posts: 38
Default Internal network-any-any-allow?

Hello,
I currently have my packet filter rules set at internal network/ any/any/allow. It is a small network envirenment and everyone on the network is trusted. Is this safe? The reason I ask is I was having trouble configuring Astaro to access some game servers we frequent using anything but internal network/any/any/allow.
Reply With Quote
  #2 (permalink)  
Old 01-25-2004, 08:20 PM
Wizard
 
Join Date: May 2003
Location: Brunswick, Maryland, USA
Posts: 2,664
Default Re: Internal network-any-any-allow?

I had mine setup that way here at the house for a while without issues..
Reply With Quote
  #3 (permalink)  
Old 01-25-2004, 08:27 PM
Member
 
Join Date: Jan 2004
Location: St.Louis, MO USA
Posts: 92
Default Re: Internal network-any-any-allow?

I have mine set that way with no problems on the outbound... and works well with UBI and others but I do have several inbound issues .... I am trying to get teamspeak working on port 8767 and no luck....
Reply With Quote
  #4 (permalink)  
Old 01-29-2004, 08:02 PM
Senior Member
 
Join Date: Jul 2002
Location: Duesseldorf/Germany
Posts: 431
Default Re: Internal network-any-any-allow?

Hi,
on problems with gameservers look on your livelog while trying to play on an other PC maybe you see that the gameserver trys to connect to you but he may try to reach you on your external address so you must forward this to your game PC.

firebear
Reply With Quote
  #5 (permalink)  
Old 01-30-2004, 11:21 PM
Junior Member
 
Join Date: Jun 2003
Posts: 8
Default Re: Internal network-any-any-allow?

Here are some of the game "services" I have setup:

Name Protocol S-Port/Client D-Port/Server
ASE Client tcp/udp 1024:65535 27243:27245
ASE Server tcp/udp 1024:65535 14690
BattleNet TCP tcp 1024:65535 6112
BattleNet UDP udp 1024:65535 6112
BF1942 udp 1024:65535 14550:14570
BF1942 Port Range udp 1024:65535 23000:23009
DirectX Net01 tcp 1024:65535 47624
DirectX Net02 udp 1024:65535 6073
DirectX Net03 tcp/udp 1024:65535 2300:2400
Gamespy Master List tcp 1024:65535 28900
Gamespy Master UDP udp 1024:65535 27900
Half Life udp 1024:65535 27010:27020
IL2 tcp/udp 1024:65535 21000
Teamspeak udp 1024:65535 8767
Valve Steam TCP tcp 1024:65535 27030:27039
Valve Steam UDP udp 1024:65535 1200

These are then lumped in a "service group" and a rule is created for that group - lan/games/any/allow

Cheers.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT. The time now is 12:12 AM.

 

Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.


These pages are specifically maintained for the discussion of firewall issues within the Open Source community, and might already reflect new alpha/beta releases under development. Please refer to our product specifications for the functionality of the actual release. Discussions of new/enhanced functionality does not constitute a commitment of Astaro, to integrate this functionality into future releases. issues within the Open Source community, and might already reflect new alpha/beta releases under development. Please refer to our product specifications for the functionality of the actual release. Discussions of new/enhanced functionality does not constitute a commitment of Astaro, to integrate this functionality into future releases.