geofxgt
(Pedro Sitan)
March 5, 2018, 8:47pm
1
NethServer Version: 7.4
Module: Firewall
I have two implementations, in different places, in one everything works properly, but in the other place, the firewall does not apply block correctly, and when I try the tail -f command in both places this is the result.
As you can see in the first site only can view the incoming conecctions, not who lan client request the conecction, in the other site I can view that information.
In the web gui I have configured this rules:
The rules are pretty same in both places, so, why the firewall has work fine in one place and in the other not?
In both places the nethserver are the gateway
Thanks for your help!
Hi Pedro,
thanks for joining the NethServer Community and welcome here!
Some of these friends may help you with your concerns
@islipfd19 @jitkian @Hunv @firsttiger @ssabbath @kolli_vasu @Imre_Bertalan @ssabbath
mrmarkuz
(Markus Neuberger)
March 10, 2018, 10:58am
3
Hi @geofxgt ,
sorry for the late answer. You may compare the firewall config of your servers:
config show firewall
db fwrules show
http://docs.nethserver.org/en/latest/firewall.html
http://docs.nethserver.org/projects/nethserver-devel/en/v7/nethserver-firewall-base.html
Are your systems both up to date? Do you use proxy and dpi?
NethServer 7.3 7.3
Module: DPI and Web Proxy
I am really struggling to block websites with nethserver. I have been a linux guru since 2009 with ebox which is now zentyal administration experience. The firewall implementation is so different and i can’t work out how it integrates with the proxy. In previous installations of zentyal being setup as a gateway and firewall with the proxy module enabled. All traffic went through the firewall before being passed to squid proxy. So basically if i blo…
Are there other differences between the 2 servers?
1 Like
geofxgt
(Pedro Sitan)
March 10, 2018, 7:27pm
4
Thanks for you reply,
In both servers I use transparent proxy, and DPI module
AFAIK the DPI module and the proxy not working together in Authenticated mode or not?
The both nethservers are updated.
geofxgt
(Pedro Sitan)
March 10, 2018, 7:56pm
6
Yes, in both sites, with the rules recommended in this post.
dnutan
(Marc)
March 10, 2018, 8:33pm
7
What’s the output of:
config getprop firewall nfqueue
geofxgt
(Pedro Sitan)
March 10, 2018, 9:37pm
8
The same result in both sites.