Old 11-30-2011, 09:33 AM   #1 (permalink)
Newbie
 
Join Date: Nov 2011
Posts: 2
jbalogwwf is on a distinguished road
Default Firewall Change (Problem) Untangle 9.1

Untangle's firewall has continually improved over time (the ability to have both simple and advanced rulesets), however the latest build has broken all of that. The fact that the interface has now switched on how one configures rules is confusing. You don't have the ability to specify permit or deny statements (check box options are very confusing).

More importantly, the granularity of the firewall rule has now been lost. For example:

I used to have SMTP (25) opened up to only allow SMTP traffic destined to my internal email server (10.10.1.2). The new untangle firewall update broke that and caused all of my mail to get blocked. Upon investigating this, I realized that not only did i have to reconfigure the rule, but the only way to allow the traffic was to do the following:

Source Interface = External
Protocol = TCP
Destination Port = 25
Destination Interface = Internal

Destination Address = removed (was 10.10.1.2)

I had to remove my destination address (10.10.1.2). The reason for having to remove this last part of the rule is that for some reason, when I am very specific to the destination address, the MAIL traffic is blocked. I have the port forward working just fine. I have tested several times using MXToolbox externally to check my mail server. I am really disappointed as now we have to have less restrictive firewall rules in order to make hosted services work.

Recommendations for Untangle Firewall:

1) Please go back to the previous build. Firewall rules in the previous versions were easy configure (having a simple and advanced option is perfect). Granularity is what made you great!

2) Port Forwarding - when port forwarding traffic, many firewalls give you the option to automatically create the associated firewall rule (usually done with a simple check box that says add firewall rule automatically). Please do this, it is a pain to have to go back and forth when port forwarding traffic to then have to get the firewall opened up as well for that same traffic.

Thank you Untangle Team!

Justin

Last edited by jbalogwwf; 11-30-2011 at 09:40 AM..
jbalogwwf is offline  
Old 11-30-2011, 09:40 AM   #2 (permalink)
Untangle Ninja
 
hlarsen's Avatar
 
Join Date: Jul 2010
Location: sfba
URLs submitted: 1
Posts: 1,137
hlarsen is on a distinguished road
Default

this bug has been reported and fixed in build5.

in build 4, you need to use Destination Address: <public IP> (rather than 10.10.1.2) for that Firewall rule. once build 5 is out, it will operate "old" way, however i don't think the new rule UI is going anywhere.
__________________
Attention: Support on the Untangle Forums is provided by volunteers and community members.
If you need official Untangle support please call or email support@untangle.com.
hlarsen is offline  
Old 11-30-2011, 09:55 AM   #3 (permalink)
Newbie
 
Join Date: Nov 2011
Posts: 1
Tangles is on a distinguished road
Default

@jbalogwwf, Fully agree with you. I voted Yes.
Tangles is offline  
Old 11-30-2011, 10:02 AM   #4 (permalink)
Untangle Junkie
 
dmorris's Avatar
 
Join Date: Nov 2006
Location: San Mateo, CA
URLs submitted: 10
Posts: 10,611
dmorris is on a distinguished road
Default

Functionally of the rules are identical in 9.1 and 9.0, with the exception of now you can match on username also in 9.1.
__________________
Attention: Support and help on the Untangle Forums is provided by
volunteers and community members like yourself.
If you need Untangle support please call or email support@untangle.com
dmorris is offline  
Old 11-30-2011, 10:13 AM   #5 (permalink)
Master Untangler
 
Join Date: Aug 2008
URLs submitted: 1
Posts: 946
far182 is on a distinguished road
Default

Quote:
Originally Posted by hlarsen View Post
this bug has been reported and fixed in build5.

in build 4, you need to use Destination Address: <public IP> (rather than 10.10.1.2) for that Firewall rule. once build 5 is out, it will operate "old" way, however i don't think the new rule UI is going anywhere.
I almost panicked until I saw this. We have a few dozen Untangle boxes configured with the firewall rules having the Internal IP Address defined in them. For us, this is the best practice. So it sounds like when the final is released, we wont have to worry about making any changes.

please correct me if I am wrong here.
far182 is offline  
Old 11-30-2011, 01:52 PM   #6 (permalink)
Untangle Ninja
 
sky-knight's Avatar
 
Join Date: Apr 2008
Location: Phoenix, AZ
URLs submitted: 8
Posts: 15,454
sky-knight is on a distinguished road
Default

The firewall has always been post-nat. Is it changing such that it matches both pre and post nat now?

I haven't done much with 9.1 other than install it. And the UI changes I've seen I like.
__________________
Rob Sandling, BS:SWE, MCP
Intouch Technology
Phone: 480-272-9889
rob@intouchtechllc.com

UntangleAppliances.com
Phone: 866-794-8879
sky-knight is offline  
Old 11-30-2011, 02:08 PM   #7 (permalink)
Untangle Junkie
 
dmorris's Avatar
 
Join Date: Nov 2006
Location: San Mateo, CA
URLs submitted: 10
Posts: 10,611
dmorris is on a distinguished road
Default

It is not changing.
It will still be pre-NAT for source address and source port, and post-NAT for destination address and destination port.
__________________
Attention: Support and help on the Untangle Forums is provided by
volunteers and community members like yourself.
If you need Untangle support please call or email support@untangle.com
dmorris is offline  
Old 11-30-2011, 02:11 PM   #8 (permalink)
Untangle Ninja
 
sky-knight's Avatar
 
Join Date: Apr 2008
Location: Phoenix, AZ
URLs submitted: 8
Posts: 15,454
sky-knight is on a distinguished road
Default

Thanks for the clarification. That's exactly the way I want it to work!
__________________
Rob Sandling, BS:SWE, MCP
Intouch Technology
Phone: 480-272-9889
rob@intouchtechllc.com

UntangleAppliances.com
Phone: 866-794-8879
sky-knight is offline  
Old 11-30-2011, 03:45 PM   #9 (permalink)
Newbie
 
Join Date: Nov 2011
Posts: 2
jbalogwwf is on a distinguished road
Default

Thank you for the clarification, i was a little concerned at first. It is good to hear that this will be fixed in the next build release.
jbalogwwf is offline  
Old 11-30-2011, 04:18 PM   #10 (permalink)
Newbie
 
Join Date: Feb 2010
URLs submitted: 4
Posts: 13
munish45 is on a distinguished road
Default Many Problems after rupgrading to 9.1

After overnight auto upgrade to 9.1, Untangle has become totally unstable.
1. System has become slow as avg load is now higher even at very low traffic and sessions.
2. Entire configuration has gone and site list in web filter are not restorable.
3. Report generation is not working. It is giving some Java error.
java.lang.Exception Unable to run daily reports: Return code: 1
4. Event log view for any module takes lot of time and shows blank.

It is contrary to the claim that new version will improve the performance.

I am unable to use the system as the behaviour is just unacceptable.

Quick Patches if any or upgrades are urgently needed or else roll back to previous version.

Regards
M.K.Gupta
munish45 is offline  
Closed Thread

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 06:26 AM.


© 2010 Untangle, Inc. All Rights Reserved.   SEO by vBSEO 3.6.0 PL2