[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[cobalt-users] IP Firewall on qube2 - Has ANYONE gotten it to work?



Ok, this is making me crazy...

I have gotten my primary & secondary up and running. IP masq & NAT all seem to be working fine. Life gets weird when I throw IP filtering into the mix.

Being somewhat new to this I went to cobalt's web site and used the firewall wizard. Input the info in my Qube 2, and voila - nothin'. Well, almost.

POP3 & SMTP seem to work, but web, ping, and DNS are toast. Disabling the IP Filter rectifies the problem.

Here's the filter configuration (IP addresses changed to protect the innocent)

1.ALLOW : Source IP = ANY : Source Port = ANY : Destination IP = 206.127.4.192/27 : Destination Port = 21 : TCP 2.ALLOW : Source IP = 10.4.0.1/14 : Source Port = ANY : Destination IP = ANY : Destination Port = 21 : TCP 3.ALLOW : Source IP = ANY : Source Port = ANY : Destination IP = 206.127.4.192/27 : Destination Port = 25 : TCP 4.ALLOW : Source IP = 10.4.0.1/14 : Source Port = ANY : Destination IP = ANY : Destinaton Port = 25 : TCP 5.ALLOW : Source IP = ANY : Source Port = ANY : Destination IP = 206.127.4.192/27 : Destination Port = 53 : TCP 6.ALLOW : Source IP = 10.4.0.1/14 : Source Port = ANY : Destination IP = ANY : Destination Port = 53 : TCP 7.ALLOW : Source IP = ANY : Source Port = ANY : Destination IP = 206.127.4.192/27 : Destination Port = 80 : TCP 8.ALLOW : Source IP = 10.4.0.1/14 : Source Port = ANY : Destination IP = ANY : Destination Port = 80 : TCP 9.ALLOW : Source IP = ANY : Source Port = ANY : Destination IP = 206.127.4.192/27 : Destination Port = 81 : TCP 10.ALLOW : Source IP = 10.4.0.1/14 : Source Port = ANY : Destination IP = ANY : Destination Port = 81 : TCP 11.ALLOW : Source IP = ANY : Source Port = ANY : Destination IP = 206.127.4.192/27 : Destination Port = 110 : TCP 12.ALLOW : Source IP = 10.4.0.1/14 : Source Port = ANY : Destination IP = ANY : Destination Port = 110 : TCP 13.ALLOW : Source IP = ANY : Source Port = ANY : Destination IP = 206.127.4.192/27 : Destination Port = 123 : TCP 14.ALLOW : Source IP = ANY : Source Port = ANY : Destination IP = 206.127.4.192/27 : Destination Port = 123 : UDP 15.ALLOW : Source IP = 10.4.0.1/14 : Source Port = ANY : Destination IP = ANY : Destination Port = 123 : TCP 16.ALLOW : Source IP = 10.4.0.1/14 : Source Port = ANY : Destination IP = ANY : Destination Port = 123 : UDP 17.ALLOW : Source IP = ANY : Source Port = ANY : Destination IP = 206.127.4.192/27 : Destination Port = 143 : TCP 18.ALLOW : Source IP = 10.4.0.1/14 : Source Port = ANY : Destination IP = ANY : Destination Port = 143 : TCP 19.ALLOW : Source IP = ANY : Source Port = ANY : Destination IP = 206.127.4.192/27 : Destination Port = 161-162 : TCP 20.ALLOW : Source IP = 10.4.0.1/14 : Source Port = ANY : Destination IP = ANY : Destination Port = 161-162 : TCP 21.ALLOW : Source IP = ANY : Source Port = ANY : Destination IP = 206.127.4.192/27 : Destination Port = ANY : ICMP 22.ALLOW : Source IP = 10.4.0.1/14 : Source Port = ANY : Destination IP = ANY : Destination Port = ANY : ICMP 23.ALLOW : Source IP = ANY : Source Port = ANY : Destination IP = 206.127.4.192/27 : Destination Port = 1025-65535 : TCP 24.ALLOW : Source IP = ANY : Source Port = ANY : Destination IP = 206.127.4.192/27 : Destination Port = 1025-65535 : UDP 25.ALLOW : Source IP = 10.4.0.1/14 : Source Port = ANY : Destination IP = ANY : Destination Port = 1025-65535 : TCP 26.ALLOW : Source IP = 10.4.0.1/14 : Source Port = ANY : Destination IP = ANY : Destination Port = 1025-65535 : UDP 27.DENY : Source IP = ANY : Source Port = ANY : Destination IP = ANY : Destination Port = ANY : ALL

I'm hoping this is a problem of my own creation...  Any ideas anyone?

Thanks,

Jeff



Jefferson K. Davis
Technology & IS Manager
Standard School District
661-392-2110