Page 2 of 2 FirstFirst 12
Results 11 to 19 of 19
  1. #11
    Untangle Junkie dmorris's Avatar
    Join Date
    Nov 2006
    Location
    San Mateo, CA
    Posts
    11,753

    Default

    Quote Originally Posted by manouche View Post
    The last rule in the rack is to Block and Log everything. The rule I have is essentially what you are proposing, and it is the first rule in the rack. It is from the specific internal interface to a specific external interface at port 22 - Pass and Log.
    Just post the event log showing that rule blocking the session in question.
    If it isn't in the event log - are you sure its being blocked by that rule?
    Attention: Support and help on the Untangle Forums is provided by volunteers and community members like yourself.
    If you need Untangle support please call or email support@untangle.com

  2. #12
    Untanglit
    Join Date
    Aug 2010
    Posts
    22

    Default

    I am not trying to block anything. I am trying to allow a pass and log from the internal interface to the external interface. Nothing shows up in the event log that indicates that it passes or logs - or blocks. If I change the rule to Block and Log, it does block and log.

  3. #13
    Untangle Junkie dmorris's Avatar
    Join Date
    Nov 2006
    Location
    San Mateo, CA
    Posts
    11,753

    Default

    Quote Originally Posted by manouche View Post
    If I change the rule to Block and Log, it does block and log.
    How do you know this? does it appear in the event log?

    Sorry without screenshots I have no further ideas on how I can help you. Good luck.
    Attention: Support and help on the Untangle Forums is provided by volunteers and community members like yourself.
    If you need Untangle support please call or email support@untangle.com

  4. #14
    Untanglit
    Join Date
    Aug 2010
    Posts
    22

    Default

    Yes. If I choose to block and log, it does block and indicates that in the event logs. However, I don't want to block, I want to pass the connection. That is what isn't happening - passing and logging. I would be glad to send a screenshot to show that the block rule does block and log, but I'm not sure how that would resolve the problem I am having.

  5. #15
    Untangle Ninja sky-knight's Avatar
    Join Date
    Apr 2008
    Location
    Phoenix, AZ
    Posts
    16,976

    Default

    Quote Originally Posted by manouche View Post
    Yes. If I choose to block and log, it does block and indicates that in the event logs. However, I don't want to block, I want to pass the connection. That is what isn't happening - passing and logging. I would be glad to send a screenshot to show that the block rule does block and log, but I'm not sure how that would resolve the problem I am having.
    You'd be showing a dev what you're seeing, and he can tell you either:

    1.) How you're misinterpreting what you're seeing
    2.) To wait for a moment while he attempts to duplicate it.

    Pictures are worth 1000 words after all, pass the detail and DMorris will set you straight. If it's a bug, he'll tell you. If you're doing something wrong, he'll tell you.

    Stop Guessing, start Troubleshooting, pass the picture.
    Rob Sandling, BS:SWE, MCP
    Intouch Technology
    Phone: 480-272-9889
    NexgenAppliances.com
    Phone: 866-794-8879

  6. #16
    Untanglit
    Join Date
    Aug 2010
    Posts
    22

    Default

    Thank you for your reply. I have attached a screenshot of the event log entry when it is blocked with a block and log rule. I also have attached a screenshot of the rule. As I have said, if I make it pass and log, it doesn't pass and it doesn't log.

    I have masked the ip of the internal server, but rest assured that I am using the correct ip in the rule. Thanks.
    Attached Images Attached Images

  7. #17
    Untangle Junkie dmorris's Avatar
    Join Date
    Nov 2006
    Location
    San Mateo, CA
    Posts
    11,753

    Default

    Well "xxx.xx.xx.xx" != "159.121.122.37"
    "xxx.xx.xx.xx" won't match anything.
    So that rule is not going to match anything.

    I thought you said this was near the top?
    According to the event log its matching rule #48, which has 47 rules above it.

    This is why we ask for screenshots.
    Last edited by dmorris; 04-06-2012 at 02:25 PM.
    Attention: Support and help on the Untangle Forums is provided by volunteers and community members like yourself.
    If you need Untangle support please call or email support@untangle.com

  8. #18
    Untanglit
    Join Date
    Aug 2010
    Posts
    22

    Default

    The rule actually uses 159.121.122.37. I only masked it for security purposes.

    I had the rule at the very top, but a post to the forums earlier suggested that I move it farther down to just before the Block all rule, which is last. I didn't think that would make a difference, but I tried it anyway and got the same result. It has been moved back to the top and I get identical results.

  9. #19
    Untangle Junkie dmorris's Avatar
    Join Date
    Nov 2006
    Location
    San Mateo, CA
    Posts
    11,753

    Default

    edit: nevermind.

    There is no way we're gonna be able to debug this with faked and random screenshots.
    I'd just call support. They'll be glad to help you.
    Last edited by dmorris; 04-06-2012 at 08:25 PM.
    Attention: Support and help on the Untangle Forums is provided by volunteers and community members like yourself.
    If you need Untangle support please call or email support@untangle.com

Page 2 of 2 FirstFirst 12

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  

SEO by vBSEO 3.6.0 PL2