Mailing List ecs-isp@2rosenthals.com Archived Message #679

From: "Massimo S." <ecs-isp@2rosenthals.com> Full Headers
Undecoded message
Subject: Re: [eCS-ISP] help about an Injoy FW rule
Date: Mon, 18 Mar 2024 09:42:37 +0100
To: eCS ISP Mailing List <ecs-isp@2rosenthals.com>



Il 17/03/2024 23:02, Steven Levine ha scritto:
In <list-9315224@2rosenthals.com>, on 03/17/24
    at 07:50 PM, "Massimo S." <ecs-isp@2rosenthals.com> said:

Hi Massimo,

the firewall in that condition do not reach the internet so each 30
minutes the fault daemon gives a reboot

OK.  The be clear, ijfw is not reaching the internet because gateway.exe
is shutting itself down and you are running with

   device-fxwrap,sys /S

in config.sys?

assist_rem_srv6_in
Destination-Port = "55000",
Source = "1.2.3.4",
Destination = "My_IP",
Rule-Action = Portmap,
Mapping-Dest-IP = "192.168.1.8",
Mapping-Dest-Port = 3389

assist_rem_srv6_out Rule-Status = Disabled
Source-Port = "3389",
Source = "192.168.1.8",
Rule-Action = Portmap,
Mapping-Dest-Port = 65488

ext_m_in
Destination-Port = "55000",
Source = "1.2.3.5",
Source-Netmask = 255.255.255.254,
Destination = "My_IP",
Rule-Action = Portmap,
Mapping-Dest-IP = "192.168.1.8",
Mapping-Dest-Port = 3389

ext_m_out
Source-Port = "3389",
Source = "192.168.1.8",
Rule-Action = Portmap,
Mapping-Dest-Port = 55000

What happens if you disable the ext_m_in rule and enable the
assist_rem_srv6_in rule?  Does gateway.exe run without dieing?

i cannot make tests, sorry
this fw server is a production machine
due to some idiot management, that place use a cloud (web) management software solution
so internet must work allmost 24hours per day

i guess the issue that create problems is the one "assist_rem_srv6_in"

If that's the only rule you added, this is probably true.

Have you checked if the recently announced ijfw 4.2.3 release has any
effect on his failure?

still not

OK.  I recommend you give it a try.  I recommend using the .zip file and
just replacing the binaries (*.exe, *.dll and *.sys).  The rest of the
files are unchanged, so your existing rules and configuration files should
works as is.

Steven

i will update it asap
massimo

Subscribe: Feed, Digest, Index.
Unsubscribe
Mail to ListMaster