Old 02-11-2010, 09:39 AM   #11 (permalink)
Untangle Ninja
 
sky-knight's Avatar
 
Join Date: Apr 2008
Location: Phoenix, AZ
URLs submitted: 8
Posts: 14,698
sky-knight is on a distinguished road
Default

No... No router worth its salt is going to send packets like that. And even if you could get it to do it, your devices won't respond to that.
__________________
Rob Sandling, BS:SWE, MCP
Intouch Technology
Phone: 480-272-9889
rob@intouchtechllc.com

UntangleAppliances.com
Phone: 866-794-8879
sky-knight is offline  
Old 02-11-2010, 12:01 PM   #12 (permalink)
Master Untangler
 
Join Date: Oct 2008
Posts: 773
pirateghost is on a distinguished road
Default

Quote:
Originally Posted by sky-knight View Post
No... No router worth its salt is going to send packets like that. And even if you could get it to do it, your devices won't respond to that.
i thought so too, but like i said, i tried to do it, and it didnt work. thanks for confirming that.
pirateghost is offline  
Old 02-11-2010, 04:24 PM   #13 (permalink)
Untanglit
 
Join Date: Feb 2010
Posts: 19
Deathcon1 is on a distinguished road
Default

I'll look into setting up another box later to handle the UPnP issue; thanks for the suggestions!

What of this other question? Does anyone know, or could point me to an FAQ I may have missed regarding whether port forwards have to be duplicated within the Firewall and vice versa or not?
Deathcon1 is offline  
Old 02-11-2010, 04:29 PM   #14 (permalink)
Untangle Ninja
 
sky-knight's Avatar
 
Join Date: Apr 2008
Location: Phoenix, AZ
URLs submitted: 8
Posts: 14,698
sky-knight is on a distinguished road
Default

The firewall module is completely independent of NAT.

Untangle port forward rules configure IPTables to translate packets. After the translation the packets are subject to the rack they are routed into by your policies.

So, if you setup your firewall to be default block, yes you need a separate firewall rule. If it's default pass you don't have to worry about it. And no, inputting NAT rules doesn't magically make firewall rules for you.
__________________
Rob Sandling, BS:SWE, MCP
Intouch Technology
Phone: 480-272-9889
rob@intouchtechllc.com

UntangleAppliances.com
Phone: 866-794-8879
sky-knight is offline  
Old 02-11-2010, 04:30 PM   #15 (permalink)
Untanglit
 
Join Date: Feb 2010
Posts: 19
Deathcon1 is on a distinguished road
Default

Thanks sky-knight!
Deathcon1 is offline  
Closed Thread

Tags
firewall, iptables, nat, upnp

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 05:07 PM.


© 2010 Untangle, Inc. All Rights Reserved.   SEO by vBSEO 3.6.0