IPTABLES startup command disabled by APPLY SETTINGS?

Post new topic   Reply to topic    DD-WRT Forum Index -> General Questions
Author Message
lr1993
DD-WRT Novice


Joined: 09 Dec 2017
Posts: 4

PostPosted: Sat Dec 09, 2017 14:58    Post subject: IPTABLES startup command disabled by APPLY SETTINGS? Reply with quote
I have a security question regarding the use of the IPTABLES command on Startup (under Administration / Commands) to provide firewall protection on two routers running DD-WRT.

My two routers are programmed to perform a series of commands starting with

iptables -I FORWARD -m state --state NEW -s 0.0.0.0/0 -j logdrop

followed by specific logaccept overrides related to my WAN side subnets.

This works fine with what appears to be one HUGE exception that I just stumbled upon. Specifically, if I perform any router configuration adjustment (followed by SAVE and APPLY SETTINGS) and I don't also do a full reboot, the firewall protections provided by the iptables commands executed at startup appear to be disabled until I do a full reboot.

I am definitely not an expert so if this is something that has been well documented (or if my iptables commands are badly engineered), please just provide a link to a discussion that will help me to sort through this better.

Here are the specs for my two routers running DD-WRT:

Software: DD-WRT v3.0-r28112 std (11/10/15)
Hardware: Asus RT-AC3200

Thanks for any help you can offer.
Sponsor
egc
DD-WRT Guru


Joined: 18 Mar 2014
Posts: 12915
Location: Netherlands

PostPosted: Sat Dec 09, 2017 16:58    Post subject: Reply with quote
For security reason use the latest build, yours is old.

Firewall commands should be saved as firewall and not as startup

_________________
Routers:Netgear R7000, R6400v1, R6400v2, EA6900 (XvortexCFE), E2000, E1200v1, WRT54GS v1.
Install guide R6400v2, R6700v3,XR300:https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=316399
Install guide R7800/XR500: https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=320614
Forum Guide Lines (important read):https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=324087
lr1993
DD-WRT Novice


Joined: 09 Dec 2017
Posts: 4

PostPosted: Sun Dec 10, 2017 3:43    Post subject: Reply with quote
egc wrote:
For security reason use the latest build, yours is old.

Firewall commands should be saved as firewall and not as startup


Thanks very much; I had overlooked the "Save Firewall" option on the Administration / Commands page. When I am back in my office I will move my iptables commands from the Startup to the Firewall area. (I was confused at first by your explanation because the Firewall box which shows the Firewall instructions-- like the startup instructions-- is only created after the "Save Firewall" command has been executed.) Also, will deal with figuring out how to upgrade to latest build when I am back in my office.
ian5142
DD-WRT Guru


Joined: 23 Oct 2013
Posts: 2319
Location: Canada

PostPosted: Sun Dec 10, 2017 3:53    Post subject: Upgrade Reply with quote
See the link in my signature on how to upgrade.

I would suggest 33772, but I do not own that particular router.

_________________
Before asking a question on the forums, update dd-wrt: Where do I download firmware? I suggest reading it all.
QCA Best WiFi Settings


Some dd-wrt wiki pages are up to date, others are not. PM me if you find an old one.

Atheros:
Netgear R7800 x3 - WDS AP / station, gateway, QoS
TP-Link Archer C7 v2 x2 - WDS Station
TP-Link TL-WDR3600 v1 - WDS Station
TP-Link 841nd v8 - NU
D-Link 615 C1/E3/I1 x 7 - 1 WDS station
D-Link 825 B1 - NU
D-Link 862L A1 x2 - WDS Station
Netgear WNDR3700v2 - NU
UBNT loco M2 x2 - airOS

Broadcom
Linksys EA6400 - Gateway, QoS
Asus N66U - AP
Netgear WNDR3700v3 - not used
MediaTek
UBNT EdgeRouter X - switch
Display posts from previous:    Page 1 of 1
Post new topic   Reply to topic    DD-WRT Forum Index -> General Questions All times are GMT

Navigation

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You can download files in this forum