Can't block ports with ip tables

Post new topic   Reply to topic    DD-WRT Forum Index -> General Questions
Goto page Previous  1, 2, 3  Next
Author Message
wrtn0b
DD-WRT Novice


Joined: 21 Nov 2019
Posts: 22

PostPosted: Thu Dec 05, 2019 22:11    Post subject: Reply with quote
it connects from different services to aws on port 8884 and plus i can't block llmnr ? i just wanted to know if there is a way to control the connection wich are going out of my desktop.
Sponsor
wrtn0b
DD-WRT Novice


Joined: 21 Nov 2019
Posts: 22

PostPosted: Sun Dec 08, 2019 21:26    Post subject: Reply with quote
anyone who can help?
Per Yngve Berg
DD-WRT Guru


Joined: 13 Aug 2013
Posts: 6870
Location: Romerike, Norway

PostPosted: Sun Dec 08, 2019 21:34    Post subject: Reply with quote
You can't specify a port without a protocol.
-p tcp or -p udp comes before --dport.
wrtn0b
DD-WRT Novice


Joined: 21 Nov 2019
Posts: 22

PostPosted: Sun Dec 08, 2019 22:07    Post subject: Reply with quote
I did specify the protocol but it's not working at moment, as you wrote before the connection has been initiated from the lan so how can i block it? it seems that ip tables are not working
Per Yngve Berg
DD-WRT Guru


Joined: 13 Aug 2013
Posts: 6870
Location: Romerike, Norway

PostPosted: Sun Dec 08, 2019 22:35    Post subject: Reply with quote
Try

ptables -I FORWARD -o `get_wanface` -i br0 -p tcp --dport 80

I'm not sure multiport and more than one protocol on one line work with dd-wrt.
wrtn0b
DD-WRT Novice


Joined: 21 Nov 2019
Posts: 22

PostPosted: Mon Dec 09, 2019 21:32    Post subject: Reply with quote
Notthing is working. I've tried almost everything but still i can't block any kind of connection from the router. This is kinda sad anyway.

For every port i try to block on every table i've got i still can log from my desktop connections going trough those ports. Doesn't matter wich table i try.

I guess i'm doing something wrong. Or just the build is bugged.
Wildlion
DD-WRT Guru


Joined: 24 May 2016
Posts: 1416

PostPosted: Mon Dec 09, 2019 23:36    Post subject: Reply with quote
You might know this already but just checking:

Are you blocking on the forwarding? (ie from your computer through the router to the internet)

Are you doing these rules BEFORE any of the related/established rules?

If you are talking connections directly too the router that is INPUT chain.

A couple of people have mentioned these things but not really explicitly.

I seriously doubt iptables is broken, I think that there is just a misunderstanding somewhere

The other thing is could we see the iptables command and an iptables -vL (before and after your change). This helps us verify and understand incase there is something small.
wrtn0b
DD-WRT Novice


Joined: 21 Nov 2019
Posts: 22

PostPosted: Tue Dec 10, 2019 19:14    Post subject: Reply with quote
Hi guys and thank you for your kindness and patient on answering me, i tried those tables on every chain i've got.
May it be the vpn is the reason why i can't control them?

My point is , if i want no ICMP for example and i set a rule for that i expect that i won't see any ICMP packet on my network. This is just an example but i still see them even after the rule.

As i said before i'm 100% wrong, so i will just reset my ip tables and restart from 0.

Any usefull advice about resetting the tables?

I won't post them because they are a shame Very HappyVery Happy due to the thousand try i have done.

Thank you so much guys!
kernel-panic69
DD-WRT Guru


Joined: 08 May 2018
Posts: 14246
Location: Texas, USA

PostPosted: Tue Dec 10, 2019 19:27    Post subject: Reply with quote
Uh, are you telling us that you didn't delete the rules that didn't work as you went along? Shocked Embarassed

Easiest way is to reset the router to defaults Cool BUT, you can list each table with rule numbers and then delete the rule number of the offending rules as well. Wink

_________________
"Life is but a fleeting moment, a vapor that vanishes quickly; All is vanity"
Contribute To DD-WRT
Pogo - A minimal level of ability is expected and needed...
DD-WRT Releases 2023 (PolitePol)
DD-WRT Releases 2023 (RSS Everything)

----------------------
Linux User #377467 counter.li.org / linuxcounter.net
wrtn0b
DD-WRT Novice


Joined: 21 Nov 2019
Posts: 22

PostPosted: Tue Dec 10, 2019 19:50    Post subject: Reply with quote
I did with some of them but i did a lot of try .

Can't i just flush them ? or should i restore it to default?
bushant
DD-WRT Guru


Joined: 18 Nov 2015
Posts: 2037

PostPosted: Tue Dec 10, 2019 19:55    Post subject: Reply with quote
wrtn0b wrote:
I won't post them because they are a shame Very HappyVery Happy due to the thousand try i have done.


When testing add rules in CLI. If they don't work they are discarded at reboot.
When they work as intended Save Firewall.
kernel-panic69
DD-WRT Guru


Joined: 08 May 2018
Posts: 14246
Location: Texas, USA

PostPosted: Tue Dec 10, 2019 21:06    Post subject: Reply with quote
wrtn0b wrote:
I did with some of them but i did a lot of try .

Can't i just flush them ? or should i restore it to default?


Flushing all the rules will force you to do a reset so you can connect to your router and the internet again....

_________________
"Life is but a fleeting moment, a vapor that vanishes quickly; All is vanity"
Contribute To DD-WRT
Pogo - A minimal level of ability is expected and needed...
DD-WRT Releases 2023 (PolitePol)
DD-WRT Releases 2023 (RSS Everything)

----------------------
Linux User #377467 counter.li.org / linuxcounter.net
Wildlion
DD-WRT Guru


Joined: 24 May 2016
Posts: 1416

PostPosted: Tue Dec 10, 2019 22:45    Post subject: Reply with quote
Sometimes pictures are helpful if you need help explaining something. I know that sometimes I read things differently than others.

But if you want to try again from the beginning it does help, because then we all know the baseline.
Alozaros
DD-WRT Guru


Joined: 16 Nov 2015
Posts: 6447
Location: UK, London, just across the river..

PostPosted: Wed Dec 11, 2019 8:16    Post subject: Reply with quote
multiport command is not present in all routers even thou it has very limited use and works just for few ports only..

p.s. i can confirm iptables work with single rule per port..block

If you need multiport, you may try to call multiport module in start up script if it helps...

_________________
Atheros
TP-Link WR740Nv1 ---DD-WRT 55630 WAP
TP-Link WR1043NDv2 -DD-WRT 55723 Gateway/DoT,Forced DNS,Ad-Block,Firewall,x4VLAN,VPN
TP-Link WR1043NDv2 -Gargoyle OS 1.15.x AP,DNS,QoS,Quotas
Qualcomm-Atheros
Netgear XR500 --DD-WRT 55779 Gateway/DoH,Forced DNS,AP Isolation,4VLAN,Ad-Block,Firewall,Vanilla
Netgear R7800 --DD-WRT 55819 Gateway/DoT,AD-Block,Forced DNS,AP&Net Isolation,x3VLAN,Firewall,Vanilla
Netgear R9000 --DD-WRT 55779 Gateway/DoT,AD-Block,AP Isolation,Firewall,Forced DNS,x2VLAN,Vanilla
Broadcom
Netgear R7000 --DD-WRT 55460 Gateway/SmartDNS/DoH,AD-Block,Firewall,Forced DNS,x3VLAN,VPN
NOT USING 5Ghz ANYWHERE
------------------------------------------------------
Stubby DNS over TLS I DNSCrypt v2 by mac913


Last edited by Alozaros on Wed Dec 11, 2019 17:45; edited 1 time in total
Alozaros
DD-WRT Guru


Joined: 16 Nov 2015
Posts: 6447
Location: UK, London, just across the river..

PostPosted: Thu Dec 12, 2019 6:52    Post subject: Reply with quote
here is how its looking my port blocking as i said one line per port blocked as multiport is not working as i want/it should...

iptables -I FORWARD -p udp --dport 25 -j DROP
iptables -I FORWARD -p tcp -o `get_wanface` --dport 25 -j REJECT
iptables -I FORWARD -p tcp --dport 25 -j DROP
iptables -I FORWARD -p tcp --dport 137 -j DROP
iptables -I FORWARD -p tcp --dport 139 -j DROP
iptables -I FORWARD -p tcp --dport 445 -j DROP
iptables -I FORWARD -p tcp --dport 502 -j DROP

_________________
Atheros
TP-Link WR740Nv1 ---DD-WRT 55630 WAP
TP-Link WR1043NDv2 -DD-WRT 55723 Gateway/DoT,Forced DNS,Ad-Block,Firewall,x4VLAN,VPN
TP-Link WR1043NDv2 -Gargoyle OS 1.15.x AP,DNS,QoS,Quotas
Qualcomm-Atheros
Netgear XR500 --DD-WRT 55779 Gateway/DoH,Forced DNS,AP Isolation,4VLAN,Ad-Block,Firewall,Vanilla
Netgear R7800 --DD-WRT 55819 Gateway/DoT,AD-Block,Forced DNS,AP&Net Isolation,x3VLAN,Firewall,Vanilla
Netgear R9000 --DD-WRT 55779 Gateway/DoT,AD-Block,AP Isolation,Firewall,Forced DNS,x2VLAN,Vanilla
Broadcom
Netgear R7000 --DD-WRT 55460 Gateway/SmartDNS/DoH,AD-Block,Firewall,Forced DNS,x3VLAN,VPN
NOT USING 5Ghz ANYWHERE
------------------------------------------------------
Stubby DNS over TLS I DNSCrypt v2 by mac913
Goto page Previous  1, 2, 3  Next Display posts from previous:    Page 2 of 3
Post new topic   Reply to topic    DD-WRT Forum Index -> General Questions All times are GMT

Navigation

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You can download files in this forum