View Full Version : Cant connect to internet with standard/enhanced ruleset
razoon
November 28th, 2006, 08:03 AM
Hello,
I am trying out LooknStop (newest version). Im really impressed by it.
I run it on a fresh XP installation on a ICS gateway.
But....my LAN computers cannot connect anymore to the internet.
Firefox or World of Warcraft wont connect.
Therefore I un-checked the 'TCP: any other packet' and 'UDP: any other packet' rules.
Then I can connect.
But I gues that is not good.
I installed the ICS rule
Any idea what is can be?
regards
Frederic
November 28th, 2006, 03:21 PM
Hi,
What are the alert you got in the log when the two rules you mentioned are enabled ?
Thanks,
Frederic
razoon
November 28th, 2006, 07:26 PM
Hi,
Well, when running Firefox on a ICS-client I get a whole buch of:
11-29-06,01:13:30 U-1756 'TCP : Any other packet ' 213.239.154.35 TCP Ports Dest:www-http=80 Src:61554
When running WoW on a client, I get these:
11-29-06,01:21:42 U-1828 'UDP : Any other UDP pack' 213.73.255.53 UDP Ports Dest:domain=53 Src:61560
This is strange, cus destination UDP port 53 is open....uhmmm
Running for example Internet Explorer on the ICS server itself is ok
So there must be a block between the ICS server and the clients... somewhere... I think.
I dont need to run LooknStop on the clients do I? On the server only suffice right?
regards
Phant0m
November 28th, 2006, 07:34 PM
For EnhancedRulesSet.rls, locate the rule ‘UDP : Authorize name resolution (DNS)’, double-click to edit it and adjust the source ports (left-side) from ‘In range A:B’ – 1024 -5000 to ‘In range A:B’ – 1024 -65535…. Save change
Locate the rule ‘TCP : Authorize most common Internet services’ and do the same change ;)
razoon
November 29th, 2006, 02:59 AM
Yay....that worked...kool...tyvm :D
Frederic
December 2nd, 2006, 11:14 AM
Hi,
For you information, the ruleset mentioned here:
http://www.looknstop.com/En/rules/rules.htm#ICS
(For Windows XP SP2 import the ruleset SharingSP2.rie.)
was supposed to do the same.
Probably you were talking about another ruleset.
Frederic
razoon
December 3rd, 2006, 02:42 AM
Hello :)
Yes these rules work indeed. I use these now and replaced the other 2 rules(which Phantom suggested) back to original state.
tyvm,
regards
vBulletin® Copyright ©2000-2012, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2012, Wilders Security Forums