Old 02-04-2012, 05:56 PM   #1 (permalink)
Master Untangler
 
Join Date: Jul 2008
Posts: 103
warhed is on a distinguished road
Default Firewall bug? No longer blocks Ext. SSH

Hello,

I have a location that has been using Untangle since 8.x
They have SSH enabled on the inside so we can tinker around.
SSH is blocked on from the outside and this works fine.
Their rule looks like this:
Source Interface: External
Destination Interface: Internal
Source Port: 22
Destination Port: 22

I recently installed 9.1 x32 on a new system.
I too enabled SSH on the Untangle device.
I created a firewall rule to block SSH from the outside.
SOURCE PORT IS MISSING
Destination port is available.
I cannot for the life of me create the rule that blocks the SSH from the outside, SSH is exposed.


Workaround:
I created a NAT rule to avoid it for now.
Protocol TCP
Port 22
Local IP 0.0.0.0

This works for now.


Am I missing something? All other Untangle I have and my friends are now missing the SOURCE Port option?
warhed is offline  
Old 02-04-2012, 06:10 PM   #2 (permalink)
Untangle Ninja

 
WebFooL's Avatar
 
Join Date: Jan 2009
Location: Sweden (Eskilstuna)
URLs submitted: 57
Posts: 3,877
WebFooL is on a distinguished road
Send a message via MSN to WebFooL
Default

Hi,

Use the packet filter to control traffic to the Untangel server it self.

And leave Sourceport empty.
Traffic often comes from a random port to a specific destination port.
WebFooL is offline  
Old 02-04-2012, 06:23 PM   #3 (permalink)
Master Untangler
 
Join Date: Jul 2008
Posts: 103
warhed is on a distinguished road
Default

I altered the rule to be as follows:
Source Address: ANY
Destination Port: 22
BLOCK

Still does not work.
warhed is offline  
Old 02-04-2012, 06:35 PM   #4 (permalink)
Untangle Junkie
 
dmorris's Avatar
 
Join Date: Nov 2006
Location: San Mateo, CA
URLs submitted: 10
Posts: 10,611
dmorris is on a distinguished road
Default

Firewall does not process traffic to Untangle, only through it.
You need to use packet filter (or just don't enable SSH in the first place).

Yes, we removed source port because we got tired of explaining that if you add "source port = 22" it will never match anything.
__________________
Attention: Support and help on the Untangle Forums is provided by
volunteers and community members like yourself.
If you need Untangle support please call or email support@untangle.com
dmorris is offline  
Old 02-04-2012, 06:51 PM   #5 (permalink)
Master Untangler
 
Join Date: Jul 2008
Posts: 103
warhed is on a distinguished road
Default

Ok, this seems a bit confusing but I am not much of a network guy.

1. Disabled my previous NAT redirect to 0.0.0.0 to try Packet Filtering.
2. Went to: http://wiki.untangle.com/index.php/Packet_Filter and was able to reach my Untangle PF rules.
3. Created Rule:
Name: BLOCK SSH from WAN
Source Address: ANY
Protocol: TCP/UDP
Destination Port: 22

*Still allows SSH from the outside and inside.
*I disabled the System Packet Filter Rules at the bottom that states
"Accept SSH traffic from all interfaces" but that denies from inside and outside.
*Would I need to create a PF rule that states Allow SSH/22 from the inside only?

I guess I am not grasping this at all (obviously). At least I have the workaround for now.
warhed is offline  
Old 02-04-2012, 06:58 PM   #6 (permalink)
Untangle Junkie
 
dmorris's Avatar
 
Join Date: Nov 2006
Location: San Mateo, CA
URLs submitted: 10
Posts: 10,611
dmorris is on a distinguished road
Default

Change everything back.
Remove all bizarre NAT policy hacks.
Remove firewall rules.
Remove custom packet filter rules.

1) Now, uncheck "Accept SSH traffic from all interfaces."
2) verify that SSH is blocked
3) Add a packet filter rule to allow "protocol = TCP AND destination port = 22 AND source interface = internal"
4) verify that SSH is accessible from the inside and not the outside.
__________________
Attention: Support and help on the Untangle Forums is provided by
volunteers and community members like yourself.
If you need Untangle support please call or email support@untangle.com
dmorris is offline  
Old 02-04-2012, 06:59 PM   #7 (permalink)
Master Untangler
 
Join Date: Jul 2008
Posts: 103
warhed is on a distinguished road
Default

Added the Source Interface to above rule from External and still no luck.

Disabled the "Accept SSH traffic from all interfaces" rule, created two new rules similar to above but deny from External and Allow from Internal Interface, still results in problems.
warhed is offline  
Old 02-04-2012, 07:02 PM   #8 (permalink)
Untangle Junkie
 
dmorris's Avatar
 
Join Date: Nov 2006
Location: San Mateo, CA
URLs submitted: 10
Posts: 10,611
dmorris is on a distinguished road
Default

Post screenshots of your configuration.

Or just email support and we'll configure it for you.

For the record, I'd recommend you not enable SSH.
__________________
Attention: Support and help on the Untangle Forums is provided by
volunteers and community members like yourself.
If you need Untangle support please call or email support@untangle.com
dmorris is offline  
Old 02-04-2012, 07:06 PM   #9 (permalink)
Master Untangler
 
Join Date: Jul 2008
Posts: 103
warhed is on a distinguished road
Default

I understand the SSH concern, but for me I am tinkering with BandwidthD atm.

Another note. The firewall does not seem to be logging any SSH attempts at all. I have setup other rules (Such as VPN and RDP to be logged) and they work, but SSH is not at all.
warhed is offline  
Old 02-04-2012, 07:10 PM   #10 (permalink)
Untangle Ninja
 
mrunkel's Avatar
 
Join Date: Jul 2008
Posts: 2,766
mrunkel is on a distinguished road
Default

Connections to and from the untangle itself do not get processed by the UVM.
__________________
m.


Big Frickin Disclaimer:
While I'm pretty sure, I can't guarantee that I know what I'm doing. There might be a better way to do this, and this way might actually suck. Make sure you understand the implications of what you're doing before trying to follow these directions.

It often helps troubleshooting if you have a good network map. Look here if you want my advice on how to draw one.
Attention: Support and help on the Untangle Forums is provided by volunteers and community members like yourself.
If you need Untangle support please call or email support@untangle.com
mrunkel is offline  
Closed Thread

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 06:55 AM.


© 2010 Untangle, Inc. All Rights Reserved.   SEO by vBSEO 3.6.0 PL2