Re: NAT and Keep State IP Rule
From: Geoff Lane (gl1public_at_btinternet.com)
Date: 01/26/04
- Next message: Beoweolf: "Re: Authentication with Firewall-1 NG with AI"
- Previous message: Duane Arnold: "Re: Zone Alarm & Wireless LANs"
- In reply to: Duane Arnold: "Re: NAT and Keep State IP Rule"
- Next in thread: Duane Arnold: "Re: NAT and Keep State IP Rule"
- Reply: Duane Arnold: "Re: NAT and Keep State IP Rule"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Date: Mon, 26 Jan 2004 02:02:05 +0000
On Mon, 26 Jan 2004 01:05:45 GMT, Duane Arnold <notme@notme.com>
wrote:
>> For practice I created an IP rule that Blocks Immediately any Protocol
>> Incoming from any Source to any destination for any port.
>>
>> I would have assumed this would effectively BLOCK my internet
>> connection but I can still surf to my hearts content so either I am
>> misunderstanding it, I've configured it wrong or it's not working
>> correctly.
>Your machine solicited the traffic from behind the router by you surfing
>the Internet or initiating the contact with an IP/Website. Your machine
>sent outbound traffic to the IP. So the router knows that and will allow
>inbound traffic from the IP your machine made contact with. A stateful
>connection or solicitation of traffic from a remote IP. The stateful
>being the outbound from your machine and the return of inbound traffic
>from the IP.
Which is the configuration option which is totally confusing me.
My IP rules page gives me the option of enabling or disabling 'Keep
State'. I have not set any outgoing IP rule or enabled any Keep State
option.
The only default Data Rule is to block ports 137-139 going to DNS
So, I haven't set any Keep State option but is seems to be doing it
anyway. If I could figure this I would be well on my way to
uderstanding it.
Geoff Lane
- Next message: Beoweolf: "Re: Authentication with Firewall-1 NG with AI"
- Previous message: Duane Arnold: "Re: Zone Alarm & Wireless LANs"
- In reply to: Duane Arnold: "Re: NAT and Keep State IP Rule"
- Next in thread: Duane Arnold: "Re: NAT and Keep State IP Rule"
- Reply: Duane Arnold: "Re: NAT and Keep State IP Rule"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|