Re: Firewalls: Rant

Liste des GroupesRevenir à c misc 
Sujet : Re: Firewalls: Rant
De : sylvia (at) *nospam* email.invalid (Sylvia Else)
Groupes : comp.misc
Date : 08. Dec 2024, 06:35:37
Autres entêtes
Message-ID : <lrkph9F1cilU1@mid.individual.net>
References : 1 2
User-Agent : Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:102.0) Gecko/20100101 Thunderbird/102.15.1
On 08-Dec-24 5:14 am, Computer Nerd Kev wrote:
Sylvia Else <sylvia@email.invalid> wrote:
Now apparently, that's not good enough, so I have to get my head around
nftables.
>
On, but wait, this is OpenWrt, which has yet another layer added - fw4.
>
And all I wanted to do was upgrade the OS to get rid of a long-standing
and very annoying race condition that would kill the WiFi at
unpredictable moments.
>
Yes, I know I'm using this router in a rather different way from the
usual, but sometimes people do things like that.
 I guess it depends how different your usage is, but if you're using
OpenWrt's fw4 firewall configuration, it's supposed to accept the
same configuration syntax as fw3, so the switch to nftables
shouldn't be causing problems if you were using that
(/etc/config/firewall).
 Mind you the increased bloat of current OpenWrt (or its included
software, including the Linux kernel, which have been getting
bigger with each version) has caused me problems. Including,
as it happens, issues with it killing the WiFi when it ran out of
RAM. Oh for a maintained software environment that doesn't have an
obesity problem...
 
I was just iptables directly, since I know how to configure it. I need to reverse the trust relationship, trusting wan, and not trusting lan. In the end I've just gone through the luci stuff, replacing lan with wan and vice versa. Now I just need to figure out the best way of blocking access from lan to some wan subnets. Probably not difficult, though it would help if I could find a defined syntax, rather than just examples. Maybe I'm just looking in the wrong place.
Sylvia.

Date Sujet#  Auteur
7 Dec 24 * Firewalls: Rant7Sylvia Else
7 Dec 24 +* Re: Firewalls: Rant4Computer Nerd Kev
8 Dec 24 i`* Re: Firewalls: Rant3Sylvia Else
8 Dec 24 i `* Re: Firewalls: Rant2Computer Nerd Kev
8 Dec 24 i  `- Re: Firewalls: Rant1Sylvia Else
12 Dec 24 `* Re: Firewalls: Rant2Salvador Mirzo
12 Dec 24  `- Re: Firewalls: Rant1Lawrence D'Oliveiro

Haut de la page

Les messages affichés proviennent d'usenet.

NewsPortal