Re: Got a Linksys BEFSX41 Router/Firewall



"Leythos" <void@xxxxxxxxxxx> wrote in message
news:ZnDmf.185300$tD4.18960@xxxxxxxxxxxxxxxxxxxxxxxxx
> In article <K6OdnepHTI2XcAfenZ2dnUVZ_tWdnZ2d@xxxxxxxxxxxx>,
> Frank@xxxxxxxxxxxxxx says...
>> Okay, I had a $50-off "Reward" card and an additional 15%-off coupon from
>> Office Depot and I didn't really need anything. So... I bought a Linksys
>> BEFSX41 Router/Firewall to play with on my 8 machine network at home (4
>> 2003
>> servers, 4 XP workstations). I already have a "real" network firewall but
>> I
>> wanted to take a look a this Linksys for possible recommendation to home
>> users with minimum needs.
>>
>> Looking for some hints on config of this thing. From what I see, it is
>> easy
>> enough to block specific protocols and IPs, but how can I block
>> "everything"
>> (all TCP/UDP ports) and then specify only what I want to allow? Is there
>> a
>> way to do that on this Linksys?
>
> You can, not sure about the SX, enter IP's to be considered Private IP,
> these won't be permitted outbound access. Same with Private Ports, ports
> that don't get outbound access.

I think the SX may be different. This is the one advertised as a "Broadband
Firewall Router". Near as I can tell, the "SX" is the disignation showing
the Firewall aspect. I can not find the "Private" word anywhere in the
config.

> The main reason to purchase this units is the dedicated IPSec tunnel
> ability for site to site VPN.

Yes, that is pretty cool. Two VPNs nonetheless.

I got a great deal, since the thing only cost me about $15 LOL.... Figured
I'd learn something about low cost consumer "network firewalls". Hehe...

I am really talking about blocking inbound traffic. It does allow blocking
ranges of ports. So... I would like to block TCP/UDP 1-65536, and then
allow specific ports as an exception. Unfortunately, I cannot find any way
to except ports. Or to make specific pass-through ports. That leaves me
with having to block ranges, for instance, like: 1-19 (allow 20, 21,23 for
ftp), then 24-24 (allow 25 for SMTP), then 26-52 (allow 53 for DNS), etc.
The problem is, the unit does not allow enough fields to get all the way up
to 65536 doing it this way.

Granted, maybe this unit is not designed to provide the capability to run a
server behind it, but really, since it is advertised as a Firewall (yeah, I
know, not certified) it would allow to close all inbound and allow
exceptions. Maybe it does, but I can't figure out how to do it.
Hence, my post :-)

After re-rereading my post, maybe what I could do is just block 1-65536 and
then "forward" the desired ports, even if they are forwarded to the same
port. Would that be the same as "allowing"?

I'm used to "rule based" firewalls.

-Frank


.



Relevant Pages

  • Re: Trouble accessing Outlook Web Access from behind firewall
    ... When starting the firewall I also set ... > rejected and dropped packets are logged, however I see nothing in my log ... > # Higher ports needed to accept incoming/outgoing calls ...
    (comp.security.firewalls)
  • Re: Can you recommend a good firewall when using FTP and Messenger voice chat over ICS?
    ... I would suggest buying a LinkSys DSL Router and using ... these ports is where you would plug your two computers. ... > I'm in a bit of a mess with my firewall situation ... ...
    (comp.security.firewalls)
  • Re: iptables configuration
    ... >> that if a 'virus/trojan' initiated a connection to the net, the firewall ... >> would not protect the LAN. ... The LAN is NATed with private IPs to one public IP. ... the ports that are used by services running on linux. ...
    (comp.os.linux.security)
  • Re: Norton Personal Firewall 2003
    ... |> First thing I would do is put the GRC test site into the Exclusions ... | ports they will not get the same result being in my blocklist, ... the firewall checks unsolicited inbound communications attempts. ...
    (comp.security.firewalls)
  • Re: How to stealth against ping/echo requests?
    ... I just started using the Online-Armor firewall. ... Some ports are even open. ... Are you behind a router? ... Every time it founds a new LAN, it asks if you want to trust it ...
    (comp.security.firewalls)

Quantcast