Posted: Thu Jun 19, 2014 8:22 Post subject: Help Please dd-wrt.v24-xxxxx_NEWD-2_K2.6 Firewall Issues
Hi Can someone tell me if they got the firewall working properly on the WNDR3400
I've tried
dd-wrt.v24-21676_NEWD-2_K2.6_mega-nv64k.bin
dd-wrt.v24-23919_NEWD-2_K2.6_big-nv64k.bin
and
dd-wrt.v24-18946_NEWD-2_K2.6_big-nv64k.bin
Each time did a 30-30-30 / Power Cycle / Log in / firware Upgrade / 30-30-30 / Power Cycle
Turned on the SPI Firewall, and used the GUI to put a couple of access restrictions in, and it didn't seem to be working properly - INPUT/FORWARD/OUTPUT Tables were empty. No rules are generated.
Posted: Fri Jun 20, 2014 16:34 Post subject: Missing Firewall Issues *SOLVED*
If you are working with the internal firewall, be aware that it doesn't get built until the router connects to the WAN.
I tested several builds:
dd-wrt.v24-18946_NEWD-2_K2.6_big-nv64k.bin
dd-wrt.v24-21676_NEWD-2_K2.6_mega-nv64k.bin
dd-wrt.v24-23919_NEWD-2_K2.6_big-nv64k.bin
dd-wrt.v24-19342_NEWD-2_K2.6_mega-nv64k.bin
(in this order-all flashed successfully)
Note: I don't think the radios were working properly on dd-wrt.v24-23919_NEWD-2_K2.6_big-nv64k.bin ~ only tested very quickly, may have done something wrong~soneone else my want to double check, but my experience seems to agree with a comment in the Wiki.
I did my testing in isolation, with the router connected only to the laptop that I used for flashing.
Given that dd-wrt is the only decent firmware that supports the WNDR3400v1 (OpenWRT & Tomato are either non-existent or based on what I can see in forums/wiki not fully functional as of 2014/06/19) I decided to revert to dd-wrt.v24-21676_NEWD-2_K2.6_mega-nv64k.bin as per the Wiki and resigned myself to writing a custom iptables script. When I connected the router to an internet connection to do additional testing, I found the firewall rules got filled in.
I hope this saves anyone else in the same situation the hours of misery that I spent endlessly searching online trying to solve this issue.
(It would be really great if people documented their tests, and there was a better indexing system so they were easier to find!)