This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

[help]60001 again!

2013:03:23-16:05:27 UTM ulogd[4440]: id="2001" severity="info" sys="SecureNet" sub="packetfilter" name="Packet dropped" action="drop" fwrule="60001" initf="eth1" srcmac="4c:ac:a:12:14:4c" dstmac="0:22:15:33:22:fa" srcip="92.238.83.22" dstip="192.168.2.248" proto="17" length="105" tos="0x00" prec="0x00" ttl="115" srcport="15402" dstport="6112" 
2013:03:23-16:05:27 UTM ulogd[4440]: id="2001" severity="info" sys="SecureNet" sub="packetfilter" name="Packet dropped" action="drop" fwrule="60001" initf="eth1" srcmac="4c:ac:a:12:14:4c" dstmac="0:22:15:33:22:fa" srcip="175.136.108.112" dstip="192.168.2.248" proto="17" length="108" tos="0x00" prec="0x00" ttl="107" srcport="6112" dstport="6112" 


how can I fix this? I already made those rules to accept the following traffic: 
those ports:
0:65###(full range) to 6112
6112 to 6112 
6112 to full range
are allowed from any to any. (Can't access the exact rules, needed to bypass as soon as possible.),
but it still get's dropped by rule 60001, what can I do to avoid this?


This thread was automatically locked due to age.
Parents
  • 192.168.2.248 is my external interface.


    does DNat have to be in place with those firewall rules?

    DNat:


    what exactly does the rule mean? I know it's a default drop, but what are the conditions for 60001?

    traffic comes from internal client, goes to an internet address.
    that address replied, but the reply is getting dropped at my external interface.. is that just because there's no DNAT rule in place?
Reply
  • 192.168.2.248 is my external interface.


    does DNat have to be in place with those firewall rules?

    DNat:


    what exactly does the rule mean? I know it's a default drop, but what are the conditions for 60001?

    traffic comes from internal client, goes to an internet address.
    that address replied, but the reply is getting dropped at my external interface.. is that just because there's no DNAT rule in place?
Children
No Data