Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Passthrough UDP 1701

Hi,

I would like to pass through 1701 UDP LAN to WAN.  It seems blocked although it is not in the log or live capture. 
Maybe related to internal VPN services?

How can I fix it?

Cheers 



This thread was automatically locked due to age.
Parents
  • Add a rule that allows the port through the firewall.

    Ian

  • I tried this as my top most rule. But still no luck. 

    I tried also only my 1702 UDP services under services. Does not help.

  • Hi,

    that rule is a good test rule but it is a security risk for production.

    Why do you want to pass that port through to the internet, a normal firewall source LAN, LAN network, destination wan, any service port 1701 (definition UDP  1:65536 to 1701). Assumption you are using the default NAT rule otherwise if you are using linked rules access will fail. If you only have one internet connection then a standard default NAT is all you need.

    Ian

  • Sure it is only a testing rule. 
    I want to make it work. Could it be that it is an issue in the current v18?


    To clarify: I want that a workstation in my LAN can connect to an internet L2TP server:

    Should not the **Default SNAT IPv4** handle this situation?! I really do not understand why my connection is dropped and not even in the logs/capture.

Reply
  • Sure it is only a testing rule. 
    I want to make it work. Could it be that it is an issue in the current v18?


    To clarify: I want that a workstation in my LAN can connect to an internet L2TP server:

    Should not the **Default SNAT IPv4** handle this situation?! I really do not understand why my connection is dropped and not even in the logs/capture.

Children