Problems using (also need some help configuring) Phant0m`` Rule-set!

Discussion in 'LnS English Forum' started by manuangi, Aug 28, 2003.

Thread Status:
Not open for further replies.
  1. manuangi

    manuangi Registered Member

    Joined:
    Jan 29, 2003
    Posts:
    148
    Location:
    Italy
    I'm running the rules which were the latest at the end of June, the ones with just an ARP rule just before the final "Block..." rule.

    Well, I downloaded the 3.1 and made the adjustments I thought were needed to keep on run smoothly: I "fixed" and enabled
    +Anti-MAC spoofing
    DNS-Allowed-1

    just as they were on June rules, as "Anti-MAC spoofing" and "DNS-Allowed-0"

    now, I noticed there are two new rules replacing the old ARP one, which I guess I have to fix and activate.
    But eventually I can't do that properly, as when I swich to the new 3.1 fixed rules, no more Internet pages open, and I can see the log using the latest rule:

    http://manuangi.altervista.org/immagini/LnSPhantom3.1NoPagesLoaded02.jpg

    192.168.0.2 is my internal IP address (while 192.168.0.1 is the Gateway), and 00:50:BA:... is my NIC's address.

    I have a Netgear DG814 Router (it's also the Internet Gateway), for an ADSL connection.

    What I did was to put my NIC's physical address (the one I used for Anti-MAC Spoofing) in "ARP: Authorize Broadcast ARP Requests"

    And I did the same in "ARP: Authorize Gateways ARP Replies.."
    In this case, I didn't know what to do, because, as explained here

    http://manuangi.altervista.org/immagini/LnSPhantom3.1PartOfARPAuthorizeGatewaysARPReplies.jpg

    I should put the Gateway Adapter address on the left, the NIC address on the right..
    But aren't they the same, in my situation?


    [...]

    Now, I imported the old ARP Rule in the 3.1, activated it and deactivated the new 2.
    I can open Internet pages, now, but something odd happen:
    The pages open really slower than usual, and in the Log section of LnS I can see:

    http://manuangi.altervista.org/immagini/LnSPhantom3.1_FFRuleRunsThoughNOTActivated.jpg

    But, friends, the "+FF..." rule is NOT active, from the Internet Filtering page! :eek:

    http://manuangi.altervista.org/immagini/LnSPhantom3.1_FFRuleNOTActivated.jpg



    Would you please help me finding out what to fix to be online running the latest 3.1?

    Thank you!!
     
  2. Phant0m

    Phant0m Registered Member

    Joined:
    Jun 7, 2003
    Posts:
    3,684
    Location:
    Canada
    Re:can't connect using (guess I need help configuring) Phant0m`` Rule-set $v3.1

    Hey manuangi

    Long time no see!

    The ARP blockings contains the Gateway’s Adapter Address, so you put that into where it’s circled red, and shown circled in blue you enter your Adapter Address…

    As for the “+FF:FF:FF:FF:FF:FF” rule, those rules which aren’t listed as configurable rules on the page and are disabled by default should not be altered unless you know what they are for and you know how to configure them…

    Regards,
     
  3. manuangi

    manuangi Registered Member

    Joined:
    Jan 29, 2003
    Posts:
    148
    Location:
    Italy
    Re:can't connect using (guess I need help configuring) Phant0m`` Rule-set $v3.1

    It's nice to see you again! :-*

    maybe I haven't made myself clear enough, in my previous post...

    I know what the ARP blockings contain...I was asking what I should put in the "ARP: Authorize Gateways ARP Replies" rule circled blocks.
    Where do I find my Gateway's Adapter Address?
    As for my Adapter Address, ie my NIC one, I can see that trough an "ipconfig /all" command...but the gateway and the router are the same machine! so...?
    Can you understand anything, from the first image in my previous post?

    As for the “+FF:FF:FF:FF:FF:FF” rule, I know it's disabled by default and, as you can see, it's disabled on my PC as well (3rd and 4th images in my previous post here)...
    BUT how is it that I can see it being called on LnS log?! It's weird!! o_O
     
  4. Phant0m

    Phant0m Registered Member

    Joined:
    Jun 7, 2003
    Posts:
    3,684
    Location:
    Canada
    Re:can't connect using (guess I need help configuring) Phant0m`` Rule-set $v3.1

    Hey manuangi

    Lets fix the ARP situation first, on the ARP logging into Look ‘n’ Stop’s Log screen, it shows you the “Ethernet Adapter Address”, you can also double click on the packet entry for “Packet’s Content”.

    On incoming Event, “Ethernet Source Address” will be the key to replace the "ARP: Authorize Gateways ARP Replies" rule source Ethernet Address which shown circled in red.
     
  5. manuangi

    manuangi Registered Member

    Joined:
    Jan 29, 2003
    Posts:
    148
    Location:
    Italy
    Re:can't connect using (guess I need help configuring) Phant0m`` Rule-set $v3.1

    thank you!

    ok, done as you said...
    this is a screenshot of my doubleclicking that entry on the log page:

    http://crom.altervista.org/immagini/LnSPhantom3.1_BlockAllRulePacketContent01.jpg

    now, let's see whether it works...
    ok, it seems to do...but, a question...where could I have got my gateway physical address, without using LnS log?

    and, now...what about the "+FF:FF:FF:FF:FF:FF" rule?
     
  6. Phant0m

    Phant0m Registered Member

    Joined:
    Jun 7, 2003
    Posts:
    3,684
    Location:
    Canada
    Re:can't connect using (guess I need help configuring) Phant0m`` Rule-set $v3.1

    Hey manuangi

    Yea what I like is Log-file sent via E-mail which captured after fresh re-boot those +FF:FF:FF:FF:FF:FF loggings, now with ARP Authorized do you still experiencing any slowdowns?
     
  7. manuangi

    manuangi Registered Member

    Joined:
    Jan 29, 2003
    Posts:
    148
    Location:
    Italy
    Re:can't connect using (guess I need help configuring) Phant0m`` Rule-set $v3.1

    well, no more +FF:FF:FF:FF:FF:FF loggings since those I saw yesterday.

    as for slowdowns...well, I guess all is ok now, I should try and see if I notice any differences having ARP authorized or not.

    what I can notice now, in my log window, is that the lines refer almost always to the same stuff:

    424 out of 453 (so far) refer to:

    http://manuangi.altervista.org/immagini/LnSPhantom3.1_UDPBlockBroadcast.jpg

    20 refer to:

    http://manuangi.altervista.org/immagini/LnSPhantom3.1_BlockAllOtherPackets.jpg

    Is it normal I have so many entries regarding the UDPBlockBroadcast rule?
    And, in the BlockAllOtherPackets one, what's happening? I can see my Gateway adapter address, my IP, a destination address like a broadcast, and a MAC 00:00:00:00:00
    Could you please explain this to me, please?

    Thanks a lot!
     
  8. Phant0m

    Phant0m Registered Member

    Joined:
    Jun 7, 2003
    Posts:
    3,684
    Location:
    Canada
    Re:can't connect using (guess I need help configuring) Phant0m`` Rule-set $v3.1

    Hey manuangi

    Yea once the ARP Rules was properly configured the slowdown or Connecting Issues should disappear since you configured up the BOOTP or DHCP and the DNS rules properly…

    It’s normal to see much broadcasts especially when you are Gateway Machine or Client Machine of LAN, if there is any issues regarding Communication from or to the Client Machine or Machines, don’t hesitate to post… :D
     
  9. manuangi

    manuangi Registered Member

    Joined:
    Jan 29, 2003
    Posts:
    148
    Location:
    Italy
    4.0

    I updated the thread subject, as we'll be talking about your 4.0's from now on (till you release some newer rules of course!) :)

    Well, to make things clear, I can tell you that my situation is
    PC <--> NetGear DG814 (router&gateway) <--> Internet
    so no specific client/server machines, just my PC.

    And yes, I properly configured the DNS rules.
    As for the BOOTP/DHCP ones, well, should I fix and activate them as well, considering my above stated situation?

    What's more, IPCONFIG /ALL says:

    http://manuangi.altervista.org/immagini/IPConfigAll.jpg

    So, DHCP should not be activated, isn't that so?
    And your related 4.0's rule?

    Thank you so much! :-*
     
  10. Phant0m

    Phant0m Registered Member

    Joined:
    Jun 7, 2003
    Posts:
    3,684
    Location:
    Canada
    Re:I need some help configuring Phant0m`` Rule-set!

    Yea, doesn’t appear to be using DHCP.
    But however what about the Default Gateway’s IP Addy?

    Deactivating the DHCP Rule(S) or configuring BLOCK Flag on them and doing; IPCONFIG /RENEW

    Do you see any BOOTP or DHCP packets being blocked? Do you experience any re-connecting issues?
     
  11. manuangi

    manuangi Registered Member

    Joined:
    Jan 29, 2003
    Posts:
    148
    Location:
    Italy
    Re:I need some help configuring Phant0m`` Rule-set!

    I'm sorry I can't understand all you say at once... :oops:

    The fact is that, right now, I've got
    BOOTP/DHCP not active
    BOOTP/DHCP. not active
    BOOTP/DHCP.. active
    BOOTP/DHCP... active

    Just as in the unmodified 4.0
    Now, do I need to activate the first two as well?
    If so, what should I write, as my BOOTP/DHCP address, seeing that it seems DHCP's not active on my system?

    What rules should I deactivate, the ".." and the "..."? Or you're talking about the first two, which I have not activated yet?

    Please, be patient with me! :doubt:

    :-*
     
  12. Phant0m

    Phant0m Registered Member

    Joined:
    Jun 7, 2003
    Posts:
    3,684
    Location:
    Canada
    Re:I need some help configuring Phant0m`` Rule-set!

    Hey manuangi

    Alright; so the first two BOOTP / DHCP rules are disabled as is by Default!?
    Now Disable the other two BOOTP / DHCP rules and renew the Adapters by using “IPCONFIG /renew”

    Do you experiencing any re-connection issues, do you see any blocking anomalies when doing that?
     
  13. manuangi

    manuangi Registered Member

    Joined:
    Jan 29, 2003
    Posts:
    148
    Location:
    Italy
    Re:I need some help configuring Phant0m`` Rule-set!

    I did as you said, disabled the ".." and "..." rules, run IPCONFIG /RENEW...and this was the answer:

    http://crom.altervista.org/immagini/IPConfigRenewNonRiuscito.jpg

    which, in English, translate as:
    "Windows IP Configuration
    Operation failed. No card is in the allowed state for execution"

    ...well? o_O

    obviously, nothing strange happened in the log window, in the while.
     
  14. Phant0m

    Phant0m Registered Member

    Joined:
    Jun 7, 2003
    Posts:
    3,684
    Location:
    Canada
    Re:I need some help configuring Phant0m`` Rule-set!

    :D

    Now re-enable those two rules you just Disabled and Apply, and re-attempt that again...
     
  15. manuangi

    manuangi Registered Member

    Joined:
    Jan 29, 2003
    Posts:
    148
    Location:
    Italy
    nothing...

    ...I get the same identical result...anything wrong o_O :doubt:
     
  16. Phant0m

    Phant0m Registered Member

    Joined:
    Jun 7, 2003
    Posts:
    3,684
    Location:
    Canada
    Re:I need some help configuring Phant0m`` Rule-set!

    Yes because you need to configure those two BOOTP / DHCP rules which is disabled by Default… ;)
     
  17. manuangi

    manuangi Registered Member

    Joined:
    Jan 29, 2003
    Posts:
    148
    Location:
    Italy
    Re:I need some help configuring Phant0m`` Rule-set!

    So, back to my previous question:

    Would you please explain that to me? :)
     
  18. Phant0m

    Phant0m Registered Member

    Joined:
    Jun 7, 2003
    Posts:
    3,684
    Location:
    Canada
    Re:I need some help configuring Phant0m`` Rule-set!

    Hey manuangi

    If I’m not mistaking when renewing the Adapters in the Look ‘n’ Stop Log screen is your Gateways BOOTP or DHCP server blockings, just configure the two configuring required BOOT / DHCP rules with the source Address on Inbound blocking, or Destination Address on Outbound blocking…

    If any troubles just E-mail me your Log-file of the Captures from renewing the Adapters…
     
  19. manuangi

    manuangi Registered Member

    Joined:
    Jan 29, 2003
    Posts:
    148
    Location:
    Italy
    Re:I need some help configuring Phant0m`` Rule-set!

    Sorry but I did not understand what I should do.
    I told you I can't renew the adapters through the IPCONFIG /RENEW command, it will show me the "failed" message. this happens always, both with the 3rd and the 4th BOOTP/DHCP rules activated and deactivated.

    as for the first and the second, I still haven't understood how I should fix them...in the log window, there's mostly that "Block: All other packets" rule whose screenshot I posted before:

    http://manuangi.altervista.org/immagini/LnSPhantom3.1_UDPBlockBroadcast.jpg

    I can't get what you mean... :doubt:
     
  20. Phant0m

    Phant0m Registered Member

    Joined:
    Jun 7, 2003
    Posts:
    3,684
    Location:
    Canada
    Re:I need some help configuring Phant0m`` Rule-set!

    Hey manuangi

    When ATTEMPTING to renew the Adapters you will see Loggings in Look ‘n’ Stop’s “Log” screen. They will represent BLOCKINGS of BOOTP or DHCP packets; there will contain IP consisting with the BOOTP or DHCP server which needs to be ADDED into the two rules “BOOTP / DHCP, and BOOTP / DHCP.” which needs to be configured and activated by Default.

    For further information read my previous post and even posts… ;)
     
  21. manuangi

    manuangi Registered Member

    Joined:
    Jan 29, 2003
    Posts:
    148
    Location:
    Italy
    Re:I need some help configuring Phant0m`` Rule-set!

    no loggings when trying to renew the adapters!

    I can't do that action, whether I have LnS running or not! That's my problem!
     
  22. Phant0m

    Phant0m Registered Member

    Joined:
    Jun 7, 2003
    Posts:
    3,684
    Location:
    Canada
    Re:I need some help configuring Phant0m`` Rule-set!

    Ohhh shoot! That’s right, yea disable ALL the BOOTP / DHCP rules, if in time needed then you can configure and activate them…
     
  23. manuangi

    manuangi Registered Member

    Joined:
    Jan 29, 2003
    Posts:
    148
    Location:
    Italy
    Re:I need some help configuring Phant0m`` Rule-set!

    You mean I should disable all 4 of them? ok, done!

    Anyway...I'm experiencing many troubles using your new 4.0 rules, my friend...
    My email client wouldn't work, nor would my download manager...I don't know...sometimes they work, sometimes they don't. but as soon as I exit LnS, all gets back to "normal life"
    I tried and switched back to the 3.1, and all worked again but I couldn't visualize all the images in this forum page, for example, not when I did a "show image" as well.
    Exited LnS, did another "show image"..everything ok again
    In the log window, just the usual "Block All Other Packets" and "UDP Block Broadcast", nothing special I mean...

    But maybe it's better if we talk to each other using ICQ, we'll surely be faster in understanding each others...what do you think?
     
  24. Phant0m

    Phant0m Registered Member

    Joined:
    Jun 7, 2003
    Posts:
    3,684
    Location:
    Canada
    Re:I need some help configuring Phant0m`` Rule-set!

    Hey manuangi

    If I had a Raw Log-file sent via E-mail I could easily have fix this, Raw Log Feature is controlled in Look ‘n’ Stop’s “Options” screen and into “Advanced Options…” area. Raw-Log files should be found in the following location \Soft4Ever\looknstop\logs\raw*.log.

    Until then first thing comes to mind, If ident requests are used by the E-mail server and you don’t configure Ident rule for it then delays and even Connection failures will occur.
     
Thread Status:
Not open for further replies.