What's new
  • SNBForums Code of Conduct

    SNBForums is a community for everyone, no matter what their level of experience.

    Please be tolerant and patient of others, especially newcomers. We are all here to share and learn!

    The rules are simple: Be patient, be nice, be helpful or be gone!

Firewall URL filter bypassed by guest networks with disabled intranet access

Climber

New Around Here
RT-AX86U on Merlin 3004.388.9_2
Guest networks with intranet access disabled seem to bypass the firewall URL filter.
On the main network the blocking works fine.
If I enable the intranet access on the guest network the blocking works fine too.
I used the GUI to add the URLs and they show up under the INPUT and FORWARD chains of iptables. So, that would mean all those rules are probably bypassed too.
Test is DNS lookup and pinging.
I disabled my own custom firewall scripts, but didn't make a difference.

I have just upgraded from 3004.388.8_4 to 9_2, but wasn't using the URL block then, so can't say if it's due to the upgrade. Haven't updated AMTM yet.
Tried searching on SNB.
Before I try a downgrade I was curious to see if someone else knows about this.

Cheers,
Peter
 
Which Guest Networks? The first Guest Network of each band behaves differently than the other 2. What did the INPUT and FORWARD rules look like, specifically? Were they only for br0 interface? Is your guest network using an interface other than br0?
 

Support SNBForums w/ Amazon

If you'd like to support SNBForums, just use this link and buy anything on Amazon. Thanks!

Sign Up For SNBForums Daily Digest

Get an update of what's new every day delivered to your mailbox. Sign up here!
Back
Top