Wilders Security Forums  

Go Back   Wilders Security Forums > Official LooknStop Firewall Forum > LnS English Forum
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old January 15th, 2009, 10:20 PM
LonkNY LonkNY is offline
Infrequent Poster
 
Join Date: Dec 2008
Posts: 14
Default Issues with NDAS networked hard drive & LnS Internet Filtering

Hi all,

I am hoping someone can help me resolve this issue. I have a new networked hard drive that uses NDAS (specifically from www.ximeta.com - using latest version - here is the manual) that works fine as long as Internet Filtering is disabled in LnS... once I enable it, the drive loses connectivity.

Here is the problem - the log entries being generated are very generic and based on several different MAC addresses... why would there be more than 2 MAC Addresses (1 for the device itself and 1 for the NDAS service on my system) involved? One of the MAC addresses is FF:FF:FF:FF:FF:FF - does this MAC address mean anything in particular? As recommended in the user guide, I have added the appropriate .EXE files to the Application Filtering exclusion list, but this has nothing to do with application filtering... it is strictly Internet Filtering in LnS...

Can I create rules that allow any traffic to and from these MAC addresses? I am concerned that I am going to screw up the rules and essentially disable Internet Filtering because the new rules I create are opening my computer up to everything... Someone in a previous post said that they used the simple LAN file sharing rules from the LnS website, but I already have these imported and it is not working. Here are some screenshots for your information:

http://i385.photobucket.com/albums/oo292/lonkny/Log.jpg

http://i385.photobucket.com/albums/o...LogEntries.jpg

I have found as many as 5 MAC addresses that are now being blocked as a result of setting up this drive & NDAS software:

04:22:B6:74:18:FD
01:80:C2:00:00:00
00:04:4B:15:B5:2C
00:0B:D0:40:52:6D
FF:FF:FF:FF:FF:FF

So I have created rules based on these MAC addresses in LnS Internet Filtering, like this:

http://i385.photobucket.com/albums/o...nkny/Rule1.jpg

Is this asking for trouble? What about the FF:FF:FF:FF:FF:FF MAC? Is this a generic MAC address or something?

What is also strange is that even though I have 6 rules for every combination of MAC addresses above, I am still logging entries for the "All other packets" bottom level rule, but the MAC addresses are the same as the MAC's in my Permit rules. The NDAS network drive is working even though the "All other packets" block rule is still being generated...

I notice also under the "Additional" column in the log, that the "Type Ethernet" being blocked is 88AD or 0026 - is there a safe way to create rules based on this (I have the RAW rule plugin installed and see that ETH rules can be setup, but have no idea how it all works)? Would this be safer than setting up rules based on the MAC addresses? What does the Type Ethernet: 88AD or 0026 mean?

Please let me know if anyone has a best practices suggestion for setting this up so it works but still keeps me protected from Internet traffic/threats.

Any help is much appreciated - thanks!

LonkNY
  #2  
Old January 16th, 2009, 01:00 AM
1hui's Avatar
1hui 1hui is offline
Regular Poster
 
Join Date: Aug 2007
Posts: 54
Default Re: Issues with NDAS networked hard drive & LnS Internet Filtering

hi LonkNY

Quote:
"Type Ethernet" being blocked is 88AD or 0026
Maybe you need to make a raw rule
you can try to allow them by this raw rule:
Name:  NDAS1.png
Views: 463
Size:  26.5 KB


Quote:
What does the Type Ethernet: 88AD or 0026 mean?
I don't known what Type Ethernet: 88AD or 0026 means.(I only known Type Ethernet 0080 or 86DD or something else )
maybe they are just for NDAS.

Quote:
MAC addresses is FF:FF:FF:FF:FF:FF - does this MAC address mean anything in particular
broadcast message will be sent to MAC "FF:FF:FF:FF:FF:FF"
sorry for my poor English.
__________________
23047-38470
  #3  
Old January 16th, 2009, 05:08 AM
ktango ktango is offline
Infrequent Poster
 
Join Date: Dec 2006
Posts: 39
Thumbs up Re: Issues with NDAS networked hard drive & LnS Internet Filtering

Hi LonkNY,

Please try to create a Raw rule allow Ximeta Netdisk protocol(Ethernet type 88AD).
Name:  Ximeta Netdisk protocol 0.jpg
Views: 468
Size:  83.6 KB
Name:  Ximeta Netdisk protocol 1.jpg
Views: 468
Size:  85.2 KB
Name:  Ximeta Netdisk protocol 2.jpg
Views: 464
Size:  85.3 KB

Last edited by ktango : January 16th, 2009 at 10:23 AM.
  #4  
Old January 16th, 2009, 08:06 AM
LonkNY LonkNY is offline
Infrequent Poster
 
Join Date: Dec 2008
Posts: 14
Default Re: Issues with NDAS networked hard drive & LnS Internet Filtering

Thank you both of you!! 1hui's RAW rule seems to work - is there a preference between your 2 methods?? Which one should I use?

Thanks again for the quick responses... much appreciated.
  #5  
Old January 16th, 2009, 08:55 AM
1hui's Avatar
1hui 1hui is offline
Regular Poster
 
Join Date: Aug 2007
Posts: 54
Default Re: Issues with NDAS networked hard drive & LnS Internet Filtering

Quote:
Originally Posted by LonkNY
is there a preference between your 2 methods?? Which one should I use?

hi LonkNY

ktango's rule is integrated.

His(maybe her) rule include the information of MAC.

04:22:B6:74:18:FD is the MAC of your PC?
__________________
23047-38470
 

Wilders Security Forums > Official LooknStop Firewall Forum > LnS English Forum « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 12:07 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums