This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

A possible bug in v18.5.2 and V19 EAP 1

Hi folks,

this is an issue I have been investigating since installing v18.5.mr2.

I have 4 security cameras on my IoT network. These cameras were accessible from my main LAN/wifi network until I installed v18.5.mr2. I had not taken the issue too seriously because I also made some changes to the firewall rules. Since then I have initiated fault with the camera company and the results came back something is blocking access to the cameras.

I have restored the firewall rules and further I have changed the rules to sue  various firewall function s all to no avail.

The cameras were setup to use ports and web sites I found during the initial installation a couple of years ago.

If I use the same wifi SSID as the cameras I can connect to the cameras without any issues, but that network is not that secure for general access.

The current configuration to access the cameras is set so that the WAN access is set to any, for cameras and PC/mac mini access.

When the WAN is set to use the camera company URLs the cameras a re not accessible internally or externally. When changed to use ANY access happens. I have investigated using logviewer and cannot see any new urls that are used by the cameras.

I do see lots of blocked broadcasts to the firewall broadcast addresses when the WAN access is restricted to the camera company URLs.

As I said at the start this issue only started with the installation of v18.5.2 MR-2.

Thoughts and suggestions where to look please.

Ian



This thread was automatically locked due to age.
Parents
  • Hi Ian, just out of curiosity, have you you tried booting v18.5.1 MR-1 (if it is still available on you're FW).

    Since you suspect the problems are due to the upgrade. Just to be sure.

     
    SFVH (SFOS 19.5.1 MR-1-Build278)  - Last (re)boot on Februari 20 2023
    Asus H410i-plus - Pentium 6605 Gold - 250GB M.2 PCIe NVMe SSD - 8GB - 3 ports
    [If any of my posts are helpful to you please use the 'Verify Answer' link]
Reply
  • Hi Ian, just out of curiosity, have you you tried booting v18.5.1 MR-1 (if it is still available on you're FW).

    Since you suspect the problems are due to the upgrade. Just to be sure.

     
    SFVH (SFOS 19.5.1 MR-1-Build278)  - Last (re)boot on Februari 20 2023
    Asus H410i-plus - Pentium 6605 Gold - 250GB M.2 PCIe NVMe SSD - 8GB - 3 ports
    [If any of my posts are helpful to you please use the 'Verify Answer' link]
Children
  • Hi Peter-Paul,

    yes it is. I will try that tomorrow morning when I have the XG to myself, also restore a backup from that time.

    Thank you for the suggestion.

    Ian

    XG115W - v19.5.1 mr-1 - Home

    If a post solves your question please use the 'Verify Answer' button.

  • Hi folks,

    did the rollback and a restore of an older configuration, no joy.

    Looks  like a rebuild of an older version pre v18.5 is required. 

    Then again another thought is a IPS change could also be the issue, very difficult to check and test.

    Ian

    XG115W - v19.5.1 mr-1 - Home

    If a post solves your question please use the 'Verify Answer' button.

  • Further testing with web exceptions, no connections.

    Logviewer shows all connections occurring, but something is failing (possible corrupting the returned traffic) when FQDN groups using the security camera domain is used in the firewall rule/s.

    Ian

    XG115W - v19.5.1 mr-1 - Home

    If a post solves your question please use the 'Verify Answer' button.