Old 03-28-2011, 07:21 PM   #11 (permalink)
Newbie
 
Join Date: Mar 2010
Location: Desert Southwest
Posts: 10
jclambert1 is on a distinguished road
Default Updated diagram

updated network diagram atatched
Attached Images
File Type: jpg Network SU - updated.jpg (63.2 KB, 8 views)
jclambert1 is offline  
Old 03-28-2011, 07:24 PM   #12 (permalink)
Newbie
 
Join Date: Mar 2010
Location: Desert Southwest
Posts: 10
jclambert1 is on a distinguished road
Default

Quote:
Originally Posted by dbunyard View Post
I'm sorry if I'm seeming ignorant here but I want to make sure I understand your setup. So the problem is the flow of traffic like this, right:
|Remote site|<==>|Internet|<==>|Local Router|<==>|Untangle|<==>|LAN|
The remote sites cannot access a server in the LAN even though a VPN is established to the local router? Sorry for the questions, I just want to make sure I understand.
BAsically yes. All traffic is flowing properly (SMB, internal web pages, printing, jabber, etc) aside from the LM on UDP shown above.
jclambert1 is offline  
Old 03-28-2011, 07:29 PM   #13 (permalink)
Untangle Ninja
 
dbunyard's Avatar
 
Join Date: Nov 2008
Location: Westerville, Ohio, USA
Posts: 1,021
dbunyard is on a distinguished road
Default

So how about a bypass rule from 10.0.1.x (and 3.x) to/from your LAN IP range?
__________________
Dan

You may one day find something interesting here. Today is not that day. Tomorrow isn't looking too good either.

Last edited by dbunyard; 03-28-2011 at 07:34 PM..
dbunyard is offline  
Old 03-28-2011, 07:46 PM   #14 (permalink)
Newbie
 
Join Date: Mar 2010
Location: Desert Southwest
Posts: 10
jclambert1 is on a distinguished road
Default

Quote:
Originally Posted by dbunyard View Post
So how about a bypass rule from 10.0.1.x (and 3.x) to/from your LAN IP range?
Bypass rule? Wouldn't that be something for firewall? I do not have that module installed. Or is this placed elsewhere in the system?

Last edited by jclambert1; 03-28-2011 at 07:46 PM.. Reason: mistyped
jclambert1 is offline  
Old 03-28-2011, 08:04 PM   #15 (permalink)
Untangle Ninja
 
dwasserman's Avatar
 
Join Date: Jun 2008
Location: Argentina
URLs submitted: 57
Posts: 3,634
dwasserman is on a distinguished road
Default

The firewall app its only a ACL subsystem, not a firewall.
In the up left corner of the rack, default rack button, show session option, you can show and debug what happen with this traffic flow.
__________________
The world is divided into 10 kinds of people, who know binary and those not
dwasserman is offline  
Old 03-28-2011, 08:20 PM   #16 (permalink)
Newbie
 
Join Date: Mar 2010
Location: Desert Southwest
Posts: 10
jclambert1 is on a distinguished road
Default

I see. I will look it over in the AM. Thanks!
jclambert1 is offline  
Old 03-28-2011, 08:35 PM   #17 (permalink)
Master Untangler
 
Join Date: Jan 2011
Posts: 626
johnsonx42 is on a distinguished road
Default

the bypass rules have nothing to do with the firewall module. they're under networking->advanced->bypass rules. these rules tell the networking code (the linux bits) to just route the packet on without passing it through the untangle vm (or in other words, to bypass the application rack). even though nothing in the uvm is blocking or really even looking at that traffic, the mere act of passing through it can foul up certain types of communication.

you can just bypass the particular udp port.
johnsonx42 is offline  
Old 03-29-2011, 06:35 AM   #18 (permalink)
Newbie
 
Join Date: Mar 2010
Location: Desert Southwest
Posts: 10
jclambert1 is on a distinguished road
Default

Quote:
Originally Posted by johnsonx42 View Post
the bypass rules have nothing to do with the firewall module. they're under networking->advanced->bypass rules. these rules tell the networking code (the linux bits) to just route the packet on without passing it through the untangle vm (or in other words, to bypass the application rack). even though nothing in the uvm is blocking or really even looking at that traffic, the mere act of passing through it can foul up certain types of communication.

you can just bypass the particular udp port.
Just bypassing the port in question worked just fine.
jclambert1 is offline  
Old 03-29-2011, 08:49 AM   #19 (permalink)
Untangle Junkie
 
dmorris's Avatar
 
Join Date: Nov 2006
Location: San Mateo, CA
URLs submitted: 10
Posts: 10,613
dmorris is on a distinguished road
Default

I suspect your netmask is too big. (likely /8 or /16 and needs to be /24)
If you want it to be bigger than /24 you'll need to add routes for 10.0.1.x and 10.0.3.x so Untangle does not think they are local.

Bypass will also work, but you'll need to do this for all services remote clients want to reach if you have it setup like that.
__________________
Attention: Support and help on the Untangle Forums is provided by
volunteers and community members like yourself.
If you need Untangle support please call or email support@untangle.com
dmorris is offline  
Closed Thread

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 03:09 AM.


© 2010 Untangle, Inc. All Rights Reserved.   SEO by vBSEO 3.6.0 PL2