Joined: 16 Mar 2019 Posts: 353 Location: Szczecin, Poland EU
Posted: Sun Jul 21, 2019 16:02 Post subject: iptables config question
I have dd-wrt in the newest version on my Netgear WNR3500L v2. I see that event in my log:
Quote:
Jul 21 13:58:46 Myrouter kern.info kernel: nf_conntrack: automatic helper assignment is deprecated and it will be removed soon. Use the iptables CT target to attach helpers instead.
I think it's something problem with iptables configuration. I have this values in iptables own configuration:
Quote:
iptables -A INPUT -s 51.255.109.168 -j REJECT
iptables -A OUTPUT -s 51.255.109.168 -j REJECT
iptables -A INPUT --proto icmp -j DROP
iptables -A OUTPUT --proto icmp -j DROP
iptables -t mangle -I POSTROUTING -o `get_wanface` -j TTL --ttl-set 129
iptables -A INPUT --proto igmp -j DROP
iptables -A OUTPUT --proto igmp -j DROP
Probably somewhere here is any mismatch. Could you hint me how Can I build optimal firewall rules for this behaviour. I need block icmp and igmp protocol, and this IP that sent me UDP packets.
Joined: 08 May 2018 Posts: 14245 Location: Texas, USA
Posted: Sun Jul 21, 2019 17:32 Post subject:
Enabling blocking anon WAN requests (ping) disables ping across the board, which is a broken feature IMHO. I have that disabled at the moment on 40352 public build, but it's not difficult to apply the proper rule(s) to block ping of death.