Lista de correo ecs-isp@2rosenthals.com Mensaje #774
De: "Massimo S." <ecs-isp@2rosenthals.com> Encabezados Completos
Mensaje no decodificado
Asunto: Re: [eCS-ISP] help about an Injoy FW rule
Fecha: Sat, 29 Jun 2024 19:16:20 +0200
Para: eCS ISP Mailing List <ecs-isp@2rosenthals.com>

Hi Steven,

i've updated Injoy FW to 4.2.3 here on one of my VM
and i discovered that it's not a free upgrade

*** WARNING: KEY HAS EXPIRED!
*** WARNING: ADVANCED FEATURES DISABLED...
*** WARNING: PROGRAM WILL TERMINATE AFTER A PAUSE...
Fatal: NAT: Too many internal clients - NAT table exhausted!

of course i had to rever back to 4.2.2 :-(

i tought it was a free update

massimo

Il 17/03/2024 23:02, Steven Levine ha scritto:
In<list-9315224@2rosenthals.com>, on 03/17/24
    at 07:50 PM, "Massimo S."<ecs-isp@2rosenthals.com>  said:

Hi Massimo,

the firewall in that condition do not reach the internet so each 30
minutes the fault daemon gives a reboot
OK.  The be clear, ijfw is not reaching the internet because gateway.exe
is shutting itself down and you are running with

   device-fxwrap,sys /S

in config.sys?

assist_rem_srv6_in
Destination-Port = "55000",
Source = "1.2.3.4",
Destination = "My_IP",
Rule-Action = Portmap,
Mapping-Dest-IP = "192.168.1.8",
Mapping-Dest-Port = 3389
assist_rem_srv6_out Rule-Status = Disabled
Source-Port = "3389",
Source = "192.168.1.8",
Rule-Action = Portmap,
Mapping-Dest-Port = 65488
ext_m_in
Destination-Port = "55000",
Source = "1.2.3.5",
Source-Netmask = 255.255.255.254,
Destination = "My_IP",
Rule-Action = Portmap,
Mapping-Dest-IP = "192.168.1.8",
Mapping-Dest-Port = 3389
ext_m_out
Source-Port = "3389",
Source = "192.168.1.8",
Rule-Action = Portmap,
Mapping-Dest-Port = 55000
What happens if you disable the ext_m_in rule and enable the
assist_rem_srv6_in rule?  Does gateway.exe run without dieing?

i guess the issue that create problems is the one "assist_rem_srv6_in"
If that's the only rule you added, this is probably true.

Have you checked if the recently announced ijfw 4.2.3 release has any
effect on his failure?
still not
OK.  I recommend you give it a try.  I recommend using the .zip file and
just replacing the binaries (*.exe, *.dll and *.sys).  The rest of the
files are unchanged, so your existing rules and configuration files should
works as is.

Steven
Subscribirse en modo directo (FEED) Subscribirse en modo resumen (DIGEST) Subscribirse en modo índice (INDEX) Desubscribirse E-mail al Listmaster