Astaro User Bulletin Board
Go Back   Astaro User Bulletin Board > Closed Forums (read only) > ASG V7.100 BETA (closed)

Welcome to the Astaro User Bulletin Board.
If this is your first visit, be sure to check out the FAQ by clicking the link above. You may have to register before you can post: click the register link above to proceed. To start viewing messages, select the forum that you want to visit from the selection below.

 
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 11-08-2007, 06:05 PM
Member
 
Join Date: May 2003
Location: Czech Republic
Posts: 67
Unhappy [7.075] How could I configure Packet filter based on interface? [NOTANISSUE]

Hi all,

do you know how can I configure packet filter based on interface ? I don't see in a window "Create new rule" added any new fields for network interface selection.

Could someone help me please ?


Thank you

Alda
  #2 (permalink)  
Old 11-08-2007, 07:56 PM
Gert Hansen's Avatar
Wizard
 
Join Date: Nov 2000
Location: Karlsruhe, Germany
Posts: 1,242
Default

Hi Alda,

thanks for the question.
We have extended the Definitions > Network objects.
you can now add an interface to every of these objects and if the object is used to create a packetfilter rule, either in Network Security > Firewall, but also in Allowed Networks in the Web and Email Security, than we add the interface additionally to it.

You are now also able to create a real 'Internet' Object using the network '0.0.0.0/0' and bind it to the external interface.

By doing this, you will not open up access to the DMZ like in the past, when you used the "Any" object.

I hope that explains it.

regards
Gert
  #3 (permalink)  
Old 11-08-2007, 09:09 PM
Member
 
Join Date: May 2003
Location: Czech Republic
Posts: 67
Default

Hi Gert,

thank you for your quick reply.
But I can't test this new feature because in the definition for network object "Any" aren't buttons Edit and Delete.

You can see it, I enclosed screen.


Thank you

Ales
Attached Images
File Type: jpg [7.075] Error for object Any.jpg (41.8 KB, 19 views)
  #4 (permalink)  
Old 11-08-2007, 09:19 PM
Moderator
 
Join Date: Apr 2001
Location: Brantford, Ontario, Canada
Posts: 809
Default

You don't want to edit Any, you should create a new one called Internet for example, like in my included screenshot. You can see I have bound it to the External interface on my firewall.
Attached Images
File Type: jpg interface-def.jpg (12.7 KB, 25 views)
__________________
7 x ASG 220, 4 x ASG 120, 2 x 25 IP, Home Unlimited Power User.
  #5 (permalink)  
Old 11-08-2007, 09:37 PM
Cath's Avatar
Senior Member
 
Join Date: Nov 2005
Location: Canada
Posts: 153
Default

This makes sense. I can see this as particularly useful when creating SNAT rules for internal servers to bind to the external alias address. (Email server)

By creating an interface definition for Internet (0.0.0.0/0) on WAN interface I no longer need to worry about extra SNAT rules to override when using VPN tunnels for remote systems to pull email off of my exchange server.
__________________
ASG 120 - 7.403
Beta 7.460
  #6 (permalink)  
Old 11-08-2007, 10:20 PM
Member
 
Join Date: May 2003
Location: Czech Republic
Posts: 67
Default

Hi Cath,

I have learned my error perhaps three seconds after I sent my reply to Gert.

My hand was quicker than my head ...

Alda
  #7 (permalink)  
Old 12-06-2007, 01:02 AM
Moderator
 
Join Date: Jul 2001
Location: southern California
Posts: 5,152
Default

Does this work with Bridged interfaces?

e.g., can I have a rule that excludes 1/2 of a bridged pair from accessing a server in the other 1/2?

Thanks,
Barry
__________________
http://DealBert.net
Home & business end-user since v1.x
  • ASL 6.3x, HP DL145 Dual Opteron, 1GB RAM, 6 gigE NICs, 50-IP Platinum License
  • ASL 7.3x, Dell PE1550 Dual PIII 1GHz, 1GB RAM, 2 NICs, 50-IP Platinum License
  • ASL 7.5x, 17-watt fanless mini-ITX system: MSI IM-945GSE-A Atom n270, 2GB RAM, Morex T3310 case. 2 Intel GigE, 3 VLANs. 80G 5200rpm 2.5" HD
    Netgear GS108T gigE VLAN switch & Linksys WRT54G WAP
    Total network infrastructure: 27 watts. 100-IP Home User. FiOS 10mb/2mb
 

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT. The time now is 06:56 PM.

 

Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.


These pages are specifically maintained for the discussion of firewall issues within the Open Source community, and might already reflect new alpha/beta releases under development. Please refer to our product specifications for the functionality of the actual release. Discussions of new/enhanced functionality does not constitute a commitment of Astaro, to integrate this functionality into future releases. issues within the Open Source community, and might already reflect new alpha/beta releases under development. Please refer to our product specifications for the functionality of the actual release. Discussions of new/enhanced functionality does not constitute a commitment of Astaro, to integrate this functionality into future releases.