PDA

View Full Version : Rule help


ellison64
August 16th, 2007, 04:33 PM
Hello..
I cant seem to be able to get visualroute lite edition to work correctly with looknstop running.The logs showed icmp type 11 being blocked so i right clicked and let looknstop create the rule and added the applications in that rule but it still doesnt seem to work.Heres some of the log....
8-16-07,21:20:06 D-225 'ICMP : All ICMP types (n' 87.127.229.33 ICMP Type:11 Code:0
See pics to see what i created.What am i doing wrong?
tia ellison

Climenole
August 16th, 2007, 05:00 PM
Hi ellison64 :)

1- Incoming packets only
2- Destination IP: equal My @

The traceroute works by sending type 8 code 0 (echo) ar different intervals
and received the answer from Internet with Type 11 code 0...

Hope this help. Lest us know.

ellison64
August 16th, 2007, 05:12 PM
Thank you very much for the rules and pics to make it easier :)
Works great now !
Thank you once again
ellison

Climenole
August 16th, 2007, 05:27 PM
Hi

I downloaded this software to check it myself...

1- You don't have to add the programs in the rule.

2- This program access the web in UDP also...

Send UDP packets from local ports to this IP addr.:unknown206.111.234.205
on port 40000 to 40002 ...

unknown206.111.234.205 is:

OrgName: Defender Technologies Group, LLC
OrgID: DTGL
Address: 44470 Chilum Place, Building 1
Address: Suite 1197
City: Ashburn
StateProv: VA
PostalCode: 20147
Country: US

ReferralServer: rwhois://rwhois.defenderhosting.com:4321/


Phone Home like E.T. ?

May be used for Domain name resolution as far as I know.
Just check the data sended by these packets...

So create a rule for this:

Protocol : UDP

Packets : in and out

addr.: form My @IP
Ports: in local

addr. all (no entry)
Ports : Between A-B : 40000 ... 40002

EDIT: phone home on port 80 (HTTP) too ... ::)

:)

ellison64
August 18th, 2007, 08:33 AM
Thanks for the extra information.I havent allowed the udp rule but it still works anyway.Visualroute does notify you whether its database/version is uptodate so it may be that calling.It works fine just allowing that type 11 for what i want it for anyway.
thanks again for your kind help.
ellison

Climenole
August 18th, 2007, 10:29 AM
Hi ellison64 :)

Yes you're right. ICMP only is correct.

:)