DrayTek UK Users' Community Forum

Help, Advice and Solutions from DrayTek Users

2850 IPv6 Firewall

  • dcrobinson1965
  • Topic Author
  • Offline
  • Junior Member
  • Junior Member
More
23 Dec 2014 17:52 #82177 by dcrobinson1965
2850 IPv6 Firewall was created by dcrobinson1965
I'm setting up IPv6 (dual stack, 6in4) on a 2850, firmware 3.6.6.

The firewall looks comprehensive like the IPv4 one, but appears to only support blocking. None of the "Block if no further match" stuff seems to work, and it appears to be wide open with no rules in place. Can anyone confirm that is in fact the case? It makes it really difficult to configure anything useful.

Please Log in or Create an account to join the conversation.

More
23 Dec 2014 22:03 #82178 by admin
Replied by admin on topic Re: 2850 IPv6 Firewall

it appears to be wide open with no rules in place



I'm not sure that's the case; why do you think that ?



Forum Administrator

Please Log in or Create an account to join the conversation.

  • dcrobinson1965
  • Topic Author
  • Offline
  • Junior Member
  • Junior Member
More
24 Dec 2014 08:43 #82179 by dcrobinson1965
Replied by dcrobinson1965 on topic Re: 2850 IPv6 Firewall

admin wrote:

it appears to be wide open with no rules in place


I'm not sure that's the case; why do you think that ?



To explain my configuration, I have a DNS server currently sitting behind IPv4 NAT (which provides me with sufficient firewall/stealthing for that), and some LAN->WAN rules to prevent the DNS behind bypassed (amongst other things).

I have now added a 6in4 tunnel and have added a couple of new rules. The first rule is supposed to allow just incoming port 53 (and is "pass immediately"). The second rule blocks the entire "/64" prefix/subnet, and is "block immediately". The DNS server is also running SSH. If I disable these rules and do an online port scan, the SSH port shows up. If I enable these rules and do a port scan, nothing gets through. Hence my observed conclusions that without the rules it is letting everything through, and that it's taking no notice of the "pass", and just doing the "block".

I've tried changing the order so that the block is first (set to "block if no further match"), and the end result is the same. I've also tried changing the interface from "WAN" to LAN/RT/VPN", in case the 6in4 tunnel doesn't count as "WAN"; however, if I do that the block firewall rules don't seem to be applied at all, which makes me think that WAN is correct.

Please Log in or Create an account to join the conversation.

More
24 Dec 2014 15:12 #82180 by admin
Replied by admin on topic Re: 2850 IPv6 Firewall
I don't quite follow the topology and couldn't tell what was ipv6/4; presumably the router is making the 6in4 tunnel. IPv6 on the
Vigors does (at least on later models) block all incoming IPv6 by default in my experience, but I've never
checked if that applies to 6in4 tunnels, only native traffic. Opening ports was only available on ipv4 on older models/earlier firmware. Sorry I can't be of more help.



Forum Administrator

Please Log in or Create an account to join the conversation.

  • dcrobinson1965
  • Topic Author
  • Offline
  • Junior Member
  • Junior Member
More
24 Dec 2014 15:31 #82181 by dcrobinson1965
Replied by dcrobinson1965 on topic Re: 2850 IPv6 Firewall
Yes, I'm using the 6in4 tunnel facility on the 2850. The tunnel gives me a /64 routed subnet. I'm assigning addresses from this to the machines in my LAN.

In summary, everything sails through the firewall by default, and the only thing that appears to work is block rules.

Please Log in or Create an account to join the conversation.

Moderators: Sami