Firewall rules priority?

(Serg) #1

My network scheme

If i set httpd-admin (NethServer web interface) to “Access only from green networks”, connection from is work. If i set:

Connection from works too.
And in shorewall’s rules i see

Why isn’t blocked and refers to the NET and not to LOC.
Sorry for my english. :slight_smile:

(Filippo Carletti) #2

You need to add a zone firewall object, with ip and device eth1.

(Serg) #3

Thank you, Filippo. I add zone. But now connections from subnet is blocked. Only if i set ip from subnet in “Allow hosts” i can connect. My zone connected to eth1, but not GREEN.
And why if i create rule:

where Host zsm -, i can connect to FW (allow hosts is clear).
But if i create:

where fw_green - firewall’s GREEN interface address, my connection is blocked?

(Filippo Carletti) #4

Firewall rules don’t allow control on traffic for the firewall itself, now. You need to use the Network services page.
I think this is confusing, we probably will extend the fiewall rules editor to handle traffic for the firewall itself.
We are open to suggestions.

(Serg) #5

But why my zone, assigned to eth1, not GREEN? It’s normal?

(Filippo Carletti) #6

I’m sorry, but I can’t understand your question.
Your green is and is a network behind a router. Using a zone you tell shorewall that it is connected to the green. By default nethserver assumes that all external network are connected to the red.
I’m not sure that this is a limit of nethserver, do you have an example of a different configuration?

(Serg) #7

Filippo, if i assign zone to eth1 and set httpd-admin (NethServer web interface) to “Access only from green networks” it block connections from to httpd-admin. But eth1 is green. May be i misunderstand something…

(Filippo Carletti) #8 is not green, is connected to green through a router.

(Serg) #9

Thank you. I thought, that all zones, assigned to local interface, must be green by default.

(Filippo Carletti) #10

You can have multiple green, but those need to be connected directly to a network interface.
I have to think about your idea, maybe it’s possible to define as green networks connected through routers.

(Serg) #11

Better manually define color of zone or optionally leave zone without color.