Posted: Sat Aug 12, 2017 5:21 Post subject: IPTables broken on Kong build?
Router Model Netgear R8000
Firmware Version DD-WRT v3.0-r33010M kongac (08/08/17)
Kernel Version Linux 4.4.79 #419 SMP Tue Aug 8 00:12:53 CEST 2017 armv7l
I have a handful of IPTable rules, specifically ones that drop/block connections to various subnets. I also have a few rules that block access to certain IP addresses.
When I typed in IPTABLES -L and ran the command, I noticed none of the rules were listed.
When I tested an IP address that was on the block list, it was actually allowed.
I saved the IPTABLES in the Firewall script. I rebooted the router.
Examples:
iptables -I FORWARD -s x.x.x.x/23 -j DROP
iptables -A FORWARD -s x.x.x.x -j DROP
EDIT: I should add that what I'm trying to do is to prevent local machines from connecting to a specific IP address. I dont want any endpoint to be able to connect to an IP, nor do I want that IP to connect to me.
Joined: 16 Nov 2015 Posts: 6409 Location: UK, London, just across the river..
Posted: Sat Aug 12, 2017 6:51 Post subject:
iptables run only on WAN side you cannot perform LAN to LAN rules... also make sure your syntax is correct..
can you post output for iptables-vnL
iptables -I FORWARD -s x.x.x.x/24 -d 192.168.1.1/24 -j DROP
those are working for me even with source only its working.. _________________ Atheros
TP-Link WR740Nv1 ---DD-WRT 55179 WAP
TP-Link WR1043NDv2 -DD-WRT 55303 Gateway/DoT,Forced DNS,Ad-Block,Firewall,x4VLAN,VPN
TP-Link WR1043NDv2 -Gargoyle OS 1.15.x AP,DNS,QoS,Quotas
Qualcomm-Atheros
Netgear XR500 --DD-WRT 55460 Gateway/DoH,Forced DNS,AP Isolation,4VLAN,Ad-Block,Firewall,Vanilla
Netgear R7800 --DD-WRT 55460 Gateway/DoT,AD-Block,Forced DNS,AP&Net Isolation,x3VLAN,Firewall,Vanilla
Netgear R9000 --DD-WRT 55363 Gateway/DoT,AD-Block,AP Isolation,Firewall,Forced DNS,x2VLAN,Vanilla
Broadcom
Netgear R7000 --DD-WRT 55460 Gateway/SmartDNS/DoH,AD-Block,Firewall,Forced DNS,x3VLAN,VPN
NOT USING 5Ghz ANYWHERE
------------------------------------------------------
Stubby DNS over TLS I DNSCrypt v2 by mac913