Remote Access - Any IP

Post new topic   Reply to topic    DD-WRT Forum Index -> General Questions
Author Message
jbkt23
DD-WRT User


Joined: 31 Dec 2018
Posts: 58

PostPosted: Tue Jul 05, 2022 22:56    Post subject: Remote Access - Any IP Reply with quote
I've left this field in it's default position of enabled as seen in png below. I would disable all wan side access as a rule but there wasn't any specific help on this setting to know what the consequences of setting it to disabled would be.

My router is used as an AP / Gateway.

Are there use case reasons to keep it enabled if the above are disabled?



RemoteAccess.png
 Description:
 Filesize:  30.4 KB
 Viewed:  1072 Time(s)

RemoteAccess.png



_________________
ARCHER-C7v5 | v3.0-r55460 std | AP Gateway
WNDR4000|v24-52189_NEWD-2_K3.x_mega|Inactive Spare
Sponsor
mrjcd
DD-WRT Guru


Joined: 31 Jan 2015
Posts: 6290
Location: Texas

PostPosted: Tue Jul 05, 2022 23:06    Post subject: Reply with quote
set any of the above for remote access
you would have to know the remote IP you was connecting from ...
...if you disbale 'Allow any Remote IP'

AND/OR

if you disable it the 'Allowed Remote IP Range' pops up for you to fill
Twisted Evil Cool

----
like so --
https://mrjcd.com/junk/dd-wrt/simplescreenrecorder.mp4
jbkt23
DD-WRT User


Joined: 31 Dec 2018
Posts: 58

PostPosted: Tue Jul 05, 2022 23:45    Post subject: Reply with quote
OK, that makes sense. It has no meaning w/o one of the other access methods being selected.

Thanks

_________________
ARCHER-C7v5 | v3.0-r55460 std | AP Gateway
WNDR4000|v24-52189_NEWD-2_K3.x_mega|Inactive Spare
the-joker
DD-WRT Developer/Maintainer


Joined: 31 Jul 2021
Posts: 2146
Location: All over YOUR webs

PostPosted: Wed Jul 06, 2022 7:44    Post subject: Re: Remote Access - Any IP Reply with quote
jbkt23 wrote:
Are there use case reasons to keep it enabled if the above are disabled?

Indeed not, this should be disabled (not disabled by toggle but grayed out so to speak) IMO because its dependent on one of the above to be enabled.

This should be relatively easy to fix and thus improve UX a little and Ive been looking at this wondering what the hell is going on, for instance;

I dont see much point of allowing telnet remote management, its not a secure method for the purpose, so unless there is an extremely valid reason to keep this (like for low end limited flash size devices), I believe this should be dropped if that's not the case.

I also have a bone to pick with the allowed IP range, for one its just IPv4 and IPv6 isnt even in the picture, nor is a remote IP where e.g. could very well not be a static IP and could be using for a DDNS solution, in that case there is no way to setup this here.
And as is I dont even know what would happen where a VPN tunnel or SSH tunnel be in use (I use SSH tunnels a great deal for general traffic), so its definitely not ideal, maybe it was years ago when this was added, this being 2022 its rather half cocked looking to me generally.

I think egc would have some valuable input here and perhaps bumping heads we can look at a better implementation. I think anyway that we could use this thread and opportunity to discuss and look at this properly now.

_________________
Saving your retinas from the burn!🔥
DD-WRT Inspired themes for routers
DD-WRT Inspired themes for the phpBB Forum
DD-WRT Inspired themes for the SVN Trac & FTP site
Join in for a chat @ #style_it_themes_public:matrix.org or #style_it_themes:discord

DD-WRT UI Themes Bug Reporting and Discussion thread

Router: ANus RT-AC68U E1 (recognized as C1)
egc
DD-WRT Guru


Joined: 18 Mar 2014
Posts: 12885
Location: Netherlands

PostPosted: Wed Jul 06, 2022 14:30    Post subject: Reply with quote
Not sure if you should remove Telnet.
Of course it is highly unsafe and I would never use it, but maybe there are scenario's where you want to remotely update and want for a short period enable remote telnet ?

What I can imagine is if you have all three items disabled, you hide "Allow any Remote IP".

Webpage is in: kromo/ddwrt/management.asp
html code in: /opt/etc/config/base.webconfig (and also the mini and micro version ?)

However as it not impacting or enhancing function it is not top priority (at least not mine Smile )

_________________
Routers:Netgear R7000, R6400v1, R6400v2, EA6900 (XvortexCFE), E2000, E1200v1, WRT54GS v1.
Install guide R6400v2, R6700v3,XR300:https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=316399
Install guide R7800/XR500: https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=320614
Forum Guide Lines (important read):https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=324087
dale_gribble39
DD-WRT Guru


Joined: 11 Jun 2022
Posts: 1935

PostPosted: Wed Jul 06, 2022 14:36    Post subject: Reply with quote
First check for caveats, i.e. that configuration not just applying to WAN access in the firewall. I don't recall it applying to LAN access, but I agree that it should be greyed out or hidden until one of the three methods are enabled. Telnet is greyed out if it is disabled for LAN access already.
_________________
"The woods are lovely, dark and deep,
But I have promises to keep,
And miles to go before I sleep,
And miles to go before I sleep." - Robert Frost

"I am one of the noticeable ones - notice me" - Dale Frances McKenzie Bozzio

<fact>code knows no gender</fact>

This is me, knowing I've ruffled your feathers, and not giving a ****
Some people are still hard-headed.

--------------------------------------
Mac Pro (Mid 2012) - Two 2.4GHz 6-Core Intel Xeon E5645 processors 64GB 1333MHz DDR3 ECC SDRAM OpenSUSE Leap 15.5
bushant
DD-WRT Guru


Joined: 18 Nov 2015
Posts: 2036

PostPosted: Wed Jul 06, 2022 15:11    Post subject: Reply with quote
Leave it alone, it"s fine. Smile
Display posts from previous:    Page 1 of 1
Post new topic   Reply to topic    DD-WRT Forum Index -> General Questions All times are GMT

Navigation

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You can download files in this forum