Temat: Gargoyle - nie działa odblokowanie portów na serwer NAS
Witam. Używam 1.5.5 (32561), by obsy. Od zawsze używałem portu 51413 na serwerze NAS gdzie chodzi Transmission. Dziś niestety transmission na serwerze oraz transmission gui zgłaszają, że dany port jest zablokowany.
Oto moje reguły firewall:
config 'defaults'
option 'syn_flood' '1'
option 'input' 'ACCEPT'
option 'output' 'ACCEPT'
option 'forward' 'REJECT'
config 'zone'
option 'name' 'lan'
option 'network' 'lan'
option 'input' 'ACCEPT'
option 'output' 'ACCEPT'
option 'forward' 'REJECT'
config 'zone'
option 'name' 'wan'
option 'network' 'wan'
option 'input' 'REJECT'
option 'output' 'ACCEPT'
option 'forward' 'REJECT'
option 'masq' '1'
option 'mtu_fix' '1'
config 'forwarding'
option 'src' 'lan'
option 'dest' 'wan'
config 'rule'
option 'name' 'Allow-DHCP-Renew'
option 'src' 'wan'
option 'proto' 'udp'
option 'dest_port' '68'
option 'target' 'ACCEPT'
option 'family' 'ipv4'
config 'rule'
option 'name' 'Allow-Ping'
option 'src' 'wan'
option 'proto' 'icmp'
option 'icmp_type' 'echo-request'
option 'family' 'ipv4'
option 'target' 'ACCEPT'
config 'rule'
option 'name' 'Allow-DHCPv6'
option 'src' 'wan'
option 'proto' 'udp'
option 'src_ip' 'fe80::/10'
option 'src_port' '547'
option 'dest_ip' 'fe80::/10'
option 'dest_port' '546'
option 'family' 'ipv6'
option 'target' 'ACCEPT'
config 'rule'
option 'name' 'Allow-ICMPv6-Input'
option 'src' 'wan'
option 'proto' 'icmp'
list 'icmp_type' 'echo-request'
list 'icmp_type' 'destination-unreachable'
list 'icmp_type' 'packet-too-big'
list 'icmp_type' 'time-exceeded'
list 'icmp_type' 'bad-header'
list 'icmp_type' 'unknown-header-type'
list 'icmp_type' 'router-solicitation'
list 'icmp_type' 'neighbour-solicitation'
list 'icmp_type' 'router-advertisement'
list 'icmp_type' 'neighbour-advertisement'
option 'limit' '1000/sec'
option 'family' 'ipv6'
option 'target' 'ACCEPT'
config 'rule'
option 'name' 'Allow-ICMPv6-Forward'
option 'src' 'wan'
option 'dest' '*'
option 'proto' 'icmp'
list 'icmp_type' 'echo-request'
list 'icmp_type' 'destination-unreachable'
list 'icmp_type' 'packet-too-big'
list 'icmp_type' 'time-exceeded'
list 'icmp_type' 'bad-header'
list 'icmp_type' 'unknown-header-type'
option 'limit' '1000/sec'
option 'family' 'ipv6'
option 'target' 'ACCEPT'
config 'include'
option 'path' '/etc/firewall.user'
config 'include'
option 'path' '/usr/lib/gargoyle_firewall_util/gargoyle_additions.firewall'
config 'rule'
option '_name' 'transmission'
option 'src' 'wan'
option 'target' 'ACCEPT'
option 'proto' 'tcp'
option 'dest_port' '51413'
config 'rule'
option '_name' 'transmission_wan'
option 'src' 'wan'
option 'target' 'ACCEPT'
option 'proto' 'tcp'
option 'dest_port' '9091'
config 'rule'
option 'target' 'ACCEPT'
option '_name' 'transmissionsynology'
option 'src' 'wan'
option 'proto' 'tcp'
option 'dest_port' '9091'
config 'remote_accept' 'ra_443_443'
option 'local_port' '443'
option 'remote_port' '443'
option 'proto' 'tcp'
option 'zone' 'wan'
config 'remote_accept' 'ra_80_80'
option 'local_port' '80'
option 'remote_port' '80'
option 'proto' 'tcp'
option 'zone' 'wan'
config 'remote_accept' 'ra_22_22'
option 'local_port' '22'
option 'remote_port' '22'
option 'proto' 'tcp'
option 'zone' 'wan'
config 'remote_accept' 'ra_openvpn'
option 'zone' 'wan'
option 'local_port' '1194'
option 'remote_port' '1194'
option 'proto' 'udp'
config 'rule'
option '_name' 'openvpn'
option 'src' 'wan'
option 'target' 'ACCEPT'
option 'proto' 'udp'
option 'dest_port' '1194'
config 'rule' 'ftp_wan'
option 'src' 'wan'
option 'target' 'ACCEPT'
option 'proto' 'tcp'
option 'dest_port' '21'
config 'zone' 'vpn_zone'
option 'name' 'vpn'
option 'network' 'vpn'
option 'input' 'ACCEPT'
option 'output' 'ACCEPT'
option 'forward' 'ACCEPT'
option 'mtu_fix' '1'
option 'masq' '1'
config 'forwarding' 'vpn_lan_forwarding'
option 'src' 'lan'
option 'dest' 'vpn'
config 'forwarding' 'vpn_wan_forwarding'
option 'src' 'vpn'
option 'dest' 'wan'
config 'redirect' 'redirect_enabled_number_0'
option 'name' 'xbox'
option 'src' 'wan'
option 'dest' 'lan'
option 'proto' 'tcp'
option 'src_dport' '3074'
option 'dest_ip' '192.168.1.102'
option 'dest_port' '3074'
config 'redirect' 'redirect_enabled_number_1'
option 'name' 'xbox'
option 'src' 'wan'
option 'dest' 'lan'
option 'proto' 'udp'
option 'src_dport' '3074'
option 'dest_ip' '192.168.1.102'
option 'dest_port' '3074'
config 'redirect' 'redirect_enabled_number_2'
option 'name' 'laptop'
option 'src' 'wan'
option 'dest' 'lan'
option 'proto' 'tcp'
option 'src_dport' '14856'
option 'dest_ip' '192.168.1.102'
option 'dest_port' '14856'
config 'redirect' 'redirect_enabled_number_3'
option 'name' 'laptop'
option 'src' 'wan'
option 'dest' 'lan'
option 'proto' 'udp'
option 'src_dport' '14856'
option 'dest_ip' '192.168.1.102'
option 'dest_port' '14856'
config 'redirect' 'redirect_enabled_number_4'
option 'name' 'torrent'
option 'src' 'wan'
option 'dest' 'lan'
option 'proto' 'tcp'
option 'src_dport' '14857'
option 'dest_ip' '192.168.1.101'
option 'dest_port' '14857'
config 'redirect' 'redirect_enabled_number_5'
option 'name' 'torrent'
option 'src' 'wan'
option 'dest' 'lan'
option 'proto' 'udp'
option 'src_dport' '14857'
option 'dest_ip' '192.168.1.101'
option 'dest_port' '14857'
config 'redirect' 'redirect_enabled_number_6'
option 'name' 'nsa310-cifs'
option 'src' 'wan'
option 'dest' 'lan'
option 'proto' 'tcp'
option 'src_dport' '445'
option 'dest_ip' '192.168.1.172'
option 'dest_port' '445'
config 'redirect' 'redirect_enabled_number_7'
option 'name' 'nsa310-cifs'
option 'src' 'wan'
option 'dest' 'lan'
option 'proto' 'udp'
option 'src_dport' '445'
option 'dest_ip' '192.168.1.172'
option 'dest_port' '445'
config 'redirect' 'redirect_enabled_number_8'
option 'name' 'nsa_hhtp'
option 'src' 'wan'
option 'dest' 'lan'
option 'proto' 'tcp'
option 'src_dport' '88'
option 'dest_ip' '192.168.1.172'
option 'dest_port' '88'
config 'redirect' 'redirect_enabled_number_9'
option 'name' 'nsa_hhtp'
option 'src' 'wan'
option 'dest' 'lan'
option 'proto' 'udp'
option 'src_dport' '88'
option 'dest_ip' '192.168.1.172'
option 'dest_port' '88'
config 'redirect' 'redirect_enabled_number_10'
option 'name' 'nsa_ftp'
option 'src' 'wan'
option 'dest' 'lan'
option 'proto' 'tcp'
option 'src_dport' '44'
option 'dest_ip' '192.168.1.172'
option 'dest_port' '21'
config 'redirect' 'redirect_enabled_number_11'
option 'name' 'nsa_ftp'
option 'src' 'wan'
option 'dest' 'lan'
option 'proto' 'udp'
option 'src_dport' '44'
option 'dest_ip' '192.168.1.172'
option 'dest_port' '21'
config 'redirect' 'redirect_enabled_number_12'
option 'name' 'utorrent_nas'
option 'src' 'wan'
option 'dest' 'lan'
option 'proto' 'tcp'
option 'src_dport' '51413'
option 'dest_ip' '192.168.1.172'
option 'dest_port' '51413'
config 'redirect' 'redirect_enabled_number_13'
option 'name' 'utorrent_nas'
option 'src' 'wan'
option 'dest' 'lan'
option 'proto' 'udp'
option 'src_dport' '51413'
option 'dest_ip' '192.168.1.172'
option 'dest_port' '51413'
config 'redirect_disabled' 'redirect_disabled_number_0'
option 'name' '192.168.1.105'
option 'src' 'wan'
option 'dest' 'lan'
option 'proto' 'tcp'
option 'src_dport' '5060'
option 'dest_ip' '192.168.1.105'
option 'dest_port' '5060'
config 'redirect_disabled' 'redirect_disabled_number_1'
option 'name' '192.168.1.105'
option 'src' 'wan'
option 'dest' 'lan'
option 'proto' 'udp'
option 'src_dport' '5060'
option 'dest_ip' '192.168.1.105'
option 'dest_port' '5060'
config 'redirect_disabled' 'redirect_disabled_number_2'
option 'name' '192.168.1.105_2'
option 'src' 'wan'
option 'dest' 'lan'
option 'proto' 'tcp'
option 'src_dport' '10000'
option 'dest_ip' '192.168.1.105'
option 'dest_port' '20000'
config 'redirect_disabled' 'redirect_disabled_number_3'
option 'name' '192.168.1.105_2'
option 'src' 'wan'
option 'dest' 'lan'
option 'proto' 'udp'
option 'src_dport' '10000'
option 'dest_ip' '192.168.1.105'
option 'dest_port' '20000'
config 'redirect_disabled' 'redirect_disabled_number_4'
option 'name' '192.168.1.105_3'
option 'src' 'wan'
option 'dest' 'lan'
option 'proto' 'tcp'
option 'src_dport' '4500'
option 'dest_ip' '192.168.1.105'
option 'dest_port' '6000'
config 'redirect_disabled' 'redirect_disabled_number_5'
option 'name' '192.168.1.105_3'
option 'src' 'wan'
option 'dest' 'lan'
option 'proto' 'udp'
option 'src_dport' '4500'
option 'dest_ip' '192.168.1.105'
option 'dest_port' '6000'
config 'redirect' 'redirect_enabled_number_14'
option 'name' 'torrentNSA'
option 'src' 'wan'
option 'dest' 'lan'
option 'proto' 'tcp'
option 'src_dport' '9091-9091'
option 'dest_port' '9091-9091'
option 'dest_ip' '192.168.1.172'
config 'redirect' 'redirect_enabled_number_15'
option 'name' 'torrentNSA'
option 'src' 'wan'
option 'dest' 'lan'
option 'proto' 'udp'
option 'src_dport' '9091-9091'
option 'dest_port' '9091-9091'
option 'dest_ip' '192.168.1.172'Czy coś jeszcze zamieścić, aby można było zdiagnozować dlaczego tak jest? Resetowałem router, samego firewalla oraz NSA i niestety nie pomogło
pozdrawiam i Wesołych życze ![]()
1.6.2.2 (r42647), by obsy oraz NAS z MiniDLNA i Transmission
wcześnej: HUB aktywny + drukarka + USB 2,5" + miniDLNA z napisami + torrent
