What's new

Firewall disabled, is it sure?

  • SNBForums Code of Conduct

    SNBForums is a community for everyone, no matter what their level of experience.

    Please be tolerant and patient of others, especially newcomers. We are all here to share and learn!

    The rules are simple: Be patient, be nice, be helpful or be gone!

lwizard

Regular Contributor
Is it sure to disable firewall?
If I do so firewall-start script does work or no? (I use it to open ports for torrent).

It seems that latest Merlin (.50) has a bug because firewall block my ip camera only when accessed from the LAN through WAN address (LAN>WAN>LAN).
Restarting the firewall after first boot fix it and also disabling the firewall.
So I think it's better disabling...
 
Do not disable the firewall. It opens your ENTIRE LAN to the Internet, and will also break a lot of features in the router that rely on firewall rules.
 
Thanks.
I will re-enable right now Port forwarding of transmission was working through firewall-start script even if firewall was disabled. Are you sure that disabling it through the web interface does disable entire firewall? It seems that port forwarding and firewall-start was working right.. maybe the firewall does not disable but apply more permitting rules??

FIREWALL OFF:
Feb 21 11:43:33 rc_service: httpd 650:notify_rc restart_firewall
Feb 21 11:43:34 start_nat_rules: apply the nat_rules(/tmp/nat_rules_eth0_eth0)!
Feb 21 11:43:34 dnsmasq[15429]: exiting on receipt of SIGTERM
Feb 21 11:43:34 dnsmasq[15513]: started, version 2.73test6 cachesize 1500
Feb 21 11:43:34 dnsmasq[15513]: warning: interface ppp1* does not currently exist
Feb 21 11:43:34 dnsmasq[15513]: asynchronous logging enabled, queue limit is 5 messages
Feb 21 11:43:34 dnsmasq-dhcp[15513]: DHCP, IP range 192.168.1.201 -- 192.168.1.249, lease time 1d
Feb 21 11:43:34 dnsmasq[15513]: read /etc/hosts - 5 addresses
Feb 21 11:43:34 dnsmasq[15513]: read /etc/hosts.dnsmasq - 9 addresses
Feb 21 11:43:34 dnsmasq-dhcp[15513]: read /etc/ethers - 9 addresses
Feb 21 11:43:34 dnsmasq[15513]: using nameserver 83.103.25.250#53 for domain local
Feb 21 11:43:34 dnsmasq[15513]: using nameserver 83.103.25.250#53 for domain fastwebnet.it
Feb 21 11:43:34 dnsmasq[15513]: using nameserver 62.101.93.101#53 for domain local
Feb 21 11:43:34 dnsmasq[15513]: using nameserver 62.101.93.101#53 for domain fastwebnet.it
Feb 21 11:43:34 dnsmasq[15513]: using nameserver 62.101.93.101#53
Feb 21 11:43:34 dnsmasq[15513]: using nameserver 83.103.25.250#53
Feb 21 11:43:35 admin: sh /opt/S95transmission.1 firewall-start

FIREWALL ON
Feb 21 11:51:03 rc_service: httpd 650:notify_rc restart_firewall
Feb 21 11:51:04 start_nat_rules: apply the nat_rules(/tmp/nat_rules_eth0_eth0)!
Feb 21 11:51:04 dnsmasq[16163]: exiting on receipt of SIGTERM
Feb 21 11:51:04 dnsmasq[16241]: started, version 2.73test6 cachesize 1500
Feb 21 11:51:04 dnsmasq[16241]: warning: interface ppp1* does not currently exist
Feb 21 11:51:04 dnsmasq[16241]: asynchronous logging enabled, queue limit is 5 messages
Feb 21 11:51:04 dnsmasq-dhcp[16241]: DHCP, IP range 192.168.1.201 -- 192.168.1.249, lease time 1d
Feb 21 11:51:04 dnsmasq[16241]: read /etc/hosts - 5 addresses
Feb 21 11:51:04 dnsmasq[16241]: read /etc/hosts.dnsmasq - 9 addresses
Feb 21 11:51:04 dnsmasq-dhcp[16241]: read /etc/ethers - 9 addresses
Feb 21 11:51:04 dnsmasq[16241]: using nameserver 83.103.25.250#53 for domain local
Feb 21 11:51:04 dnsmasq[16241]: using nameserver 83.103.25.250#53 for domain fastwebnet.it
Feb 21 11:51:04 dnsmasq[16241]: using nameserver 62.101.93.101#53 for domain local
Feb 21 11:51:04 dnsmasq[16241]: using nameserver 62.101.93.101#53 for domain fastwebnet.it
Feb 21 11:51:04 dnsmasq[16241]: using nameserver 62.101.93.101#53
Feb 21 11:51:04 dnsmasq[16241]: using nameserver 83.103.25.250#53
Feb 21 11:51:06 admin: sh /opt/S95transmission.1 firewall-start

Also there is an incoerence in URL filter. If I disable firewall URL filter is cleared, but if I add something in URL filter with firewall disabled, the url is filtered and firewall still disabled!

Merlin can you imagine why my ipcam is not accessible from LAN>WAN>LAN (but is accessible from LAN and WAN) untill firewall is restarted after first boot?
I also had a temporary internet hangs yesterday which solved in few minutes.
Does this mean anything:
Feb 21 11:43:34 dnsmasq[15513]: warning: interface ppp1* does not currently exist
?

Thanks!
 
Last edited:

Similar threads

Latest threads

Sign Up For SNBForums Daily Digest

Get an update of what's new every day delivered to your mailbox. Sign up here!
Top