Astaro User Bulletin Board
Go Back   Astaro User Bulletin Board > Closed Forums (read only) > ASG V7.500 BETA (closed)

Welcome to the Astaro User Bulletin Board.
If this is your first visit, be sure to check out the FAQ by clicking the link above. You may have to register before you can post: click the register link above to proceed. To start viewing messages, select the forum that you want to visit from the selection below.

 
 
LinkBack Thread Tools Display Modes
  #21 (permalink)  
Old 07-03-2009, 05:31 PM
Billybob's Avatar
Wizard
 
Join Date: Jul 2006
Location: United States
Posts: 637
Default

Did some more testing on the port 80 mystery. I disabled http proxy and disabled all traffic for my xp client to dmz. When you type start run \\192.168.1.101 It generates netbios/port 445 traffic and then suddenly switches to port 8080 and queries the firewall itself at 192.168.0.1. Another strange windows behavior I guess. Screenshot attached.
Attached Images
File Type: jpg packetf.jpg (97.4 KB, 4 views)
  #22 (permalink)  
Old 07-03-2009, 06:50 PM
Super Moderator
 
Join Date: Feb 2009
Location: In a galaxy far far away
Posts: 857
Default

Quote:
Originally Posted by Billybob View Post
Did some more testing on the port 80 mystery. I disabled http proxy and disabled all traffic for my xp client to dmz. When you type start run \\192.168.1.101 It generates netbios/port 445 traffic and then suddenly switches to port 8080 and queries the firewall itself at 192.168.0.1. Another strange windows behavior I guess. Screenshot attached.


If that's the case then yes the traffic is blocked

I can confirm that.I've disabled the http proxy and IPS and logged traffic

Code:
18:43:10	Packetfilter rule #9	TCP	
192.168.2.31	:	3354
→	
172.16.1.2	:	80
[SYN]	len=48	ttl=127	tos=0x00	srcmac=00:1f:d0:0a:9a:89	dstmac=00:b0:c2:02:e4:4f
18:43:10	Packetfilter rule #9	TCP	
192.168.2.31	:	3354
→	
172.16.1.2	:	80
[SYN]	len=48	ttl=127	tos=0x00	srcmac=00:1f:d0:0a:9a:89	dstmac=00:b0:c2:02:e4:4f
18:43:10	Packetfilter rule #9	TCP	
192.168.2.31	:	3354
→	
172.16.1.2	:	80
[SYN]	len=48	ttl=127	tos=0x00	srcmac=00:1f:d0:0a:9a:89
The log includes netbios as well but I didn't include here as it's expected to see netbios traffic

I get a challenge for my password and username on the box. Strangely enough I can see port 80 (not 8080) on the log

Stll that doesn;'t explain why my vista box can access with no issues when ips and HTTP proxy are enabled
__________________

Running Astaro ASG virtual appliance | Home power user 100 IP license
Intel Dual Core 2.4GHz (800MHz) | 4GB (2 x 2GB) PC2-6400 800Mhz 5-5-5-18 | WD 160GB |3 x Intel Pro/1000

Last edited by wingman; 07-07-2009 at 11:36 PM.
  #23 (permalink)  
Old 07-07-2009, 09:29 PM
Super Moderator
 
Join Date: Feb 2009
Location: In a galaxy far far away
Posts: 857
Default

to me this is a bug so I've changed the name

Any luck Billybob with the testing from ur side?
__________________

Running Astaro ASG virtual appliance | Home power user 100 IP license
Intel Dual Core 2.4GHz (800MHz) | 4GB (2 x 2GB) PC2-6400 800Mhz 5-5-5-18 | WD 160GB |3 x Intel Pro/1000

Last edited by wingman; 07-07-2009 at 11:35 PM.
  #24 (permalink)  
Old 07-08-2009, 03:02 AM
Billybob's Avatar
Wizard
 
Join Date: Jul 2006
Location: United States
Posts: 637
Default

Quote:
Originally Posted by wingman View Post
to me this is a bug so I've changed the name
Any luck Billybob with the testing from ur side?
Sorry about not getting back sooner. Was trying to have a regular life on the 4th of July weekend This is definitely a bug, I think they are just waiting on your confirmation if IPS is what is really blocking your access and if it is, are both vista and xp affected. Just a little more info.

When I tested this I couldn't get to my share on dmz using vista or xp. In vista, I would get an explorer window and it would hang generating the
sid="529" NETBIOS DCERPC NCACN-IP-TCP srvsvc NetrShareEnum null policy handle attempt
xp generates the sid="466" ICMP L3retriever Ping.

Although sid 466 is not set to block, it still blocked my requests but thats a different bug.

Quote:
Originally Posted by wingman View Post
I get a challenge for my password and username on the box. Strangely enough I can see port 80 (not 8080) on the log
I had port 8080 in my browser so it is going to 8080 for me and 80 for you.

Last edited by Billybob; 07-08-2009 at 04:16 PM.
  #25 (permalink)  
Old 07-08-2009, 09:23 AM
Super Moderator
 
Join Date: Feb 2009
Location: In a galaxy far far away
Posts: 857
Default

I will test again and post my results here
__________________

Running Astaro ASG virtual appliance | Home power user 100 IP license
Intel Dual Core 2.4GHz (800MHz) | 4GB (2 x 2GB) PC2-6400 800Mhz 5-5-5-18 | WD 160GB |3 x Intel Pro/1000
  #26 (permalink)  
Old 07-08-2009, 08:08 PM
Super Moderator
 
Join Date: Feb 2009
Location: In a galaxy far far away
Posts: 857
Default

I've disabled both IPS and Proxy and it doesn't work.I guess it's normal since I dont have any pf allowing ports 80,8080
I can see the traffic being blocked including port 80
__________________

Running Astaro ASG virtual appliance | Home power user 100 IP license
Intel Dual Core 2.4GHz (800MHz) | 4GB (2 x 2GB) PC2-6400 800Mhz 5-5-5-18 | WD 160GB |3 x Intel Pro/1000
  #27 (permalink)  
Old 07-09-2009, 05:52 PM
Super Moderator
 
Join Date: Feb 2009
Location: In a galaxy far far away
Posts: 857
Default

issue not solved on 7.470 update
I can connect with no issues on devices on the same subnet (192.168.2.x)
Astaro doesn't log (packet filter) anything when the connection is initiated from the vista to the media center .
When the connection is initiated from the xp client then I can see allowed connection as Billybob mentioned
__________________

Running Astaro ASG virtual appliance | Home power user 100 IP license
Intel Dual Core 2.4GHz (800MHz) | 4GB (2 x 2GB) PC2-6400 800Mhz 5-5-5-18 | WD 160GB |3 x Intel Pro/1000

Last edited by wingman; 07-09-2009 at 10:31 PM.
  #28 (permalink)  
Old 07-11-2009, 08:46 PM
Super Moderator
 
Join Date: Feb 2009
Location: In a galaxy far far away
Posts: 857
Default

same error when trying to connect

Code:
2009:07:11-20:45:03 stuffman httpproxy[4120]: [0xb15d9870] send_request_headers (request.c:171) write: Connection refused 
2009:07:11-20:45:03 stuffman httpproxy[4120]: id="0002" severity="info" sys="SecureWeb" sub="http" name="web request blocked" action="block" method="OPTIONS" srcip="192.168.2.31" user="" statuscode="502" cached="0" profile="REF_TJkZFLrkmc (Zone 1 Proxy filter)" filteraction="REF_KvAnposSQm (Zone 1 Filter)" size="2135" time="3 ms" request="0xb15d9870" url="http://172.16.1.2/" exceptions="" error="" category="9998" reputation="neutral" categoryname="Uncategorized"
__________________

Running Astaro ASG virtual appliance | Home power user 100 IP license
Intel Dual Core 2.4GHz (800MHz) | 4GB (2 x 2GB) PC2-6400 800Mhz 5-5-5-18 | WD 160GB |3 x Intel Pro/1000
  #29 (permalink)  
Old 07-12-2009, 07:24 PM
Super Moderator
 
Join Date: Feb 2009
Location: In a galaxy far far away
Posts: 857
Default

Workaround: I can access the shared folder by removing the DMZ client from the IPS
__________________

Running Astaro ASG virtual appliance | Home power user 100 IP license
Intel Dual Core 2.4GHz (800MHz) | 4GB (2 x 2GB) PC2-6400 800Mhz 5-5-5-18 | WD 160GB |3 x Intel Pro/1000
  #30 (permalink)  
Old 08-02-2009, 05:27 PM
Super Moderator
 
Join Date: Feb 2009
Location: In a galaxy far far away
Posts: 857
Default

I 've recently installed windows 7 RC and I am not facing the issue. I am able to rdp to the dmz and access the shared resources.

I assume it was some kind of bug.

Thanks for your help
__________________

Running Astaro ASG virtual appliance | Home power user 100 IP license
Intel Dual Core 2.4GHz (800MHz) | 4GB (2 x 2GB) PC2-6400 800Mhz 5-5-5-18 | WD 160GB |3 x Intel Pro/1000
 

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT. The time now is 09:58 PM.

 

Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.


These pages are specifically maintained for the discussion of firewall issues within the Open Source community, and might already reflect new alpha/beta releases under development. Please refer to our product specifications for the functionality of the actual release. Discussions of new/enhanced functionality does not constitute a commitment of Astaro, to integrate this functionality into future releases. issues within the Open Source community, and might already reflect new alpha/beta releases under development. Please refer to our product specifications for the functionality of the actual release. Discussions of new/enhanced functionality does not constitute a commitment of Astaro, to integrate this functionality into future releases.