Do any of these rules block access to the WAN?
-
I’d be much obliged, if you could look over the following rules for my guest Wi-Fi network. I am wondering, whether I am missing something that might implicitly block access to the WAN interface from that subnet.
-
@DominikHoffmann while that rule blocking dns 53 could stop access to your wan address on 53.. It would block access to anything via 53 other than what you allowed above it on 53..
Keep in mind none of these rules have ever even been evaluated, see the 0/0 in the states column, if you see 0/0 that 2nd zero means no traffic at all has ever triggered those rules.
you would think that last one there would of been triggered if there was any traffic being seen on this interface.. Are you not the same person asking if dhcp was blocked by any of these rules?
I don't see any triggers on any of these rules.. Do you have maybe some rule in floating that is triggering before the traffic would be evaluated by these rules?
-
@johnpoz: Thanks your keen eye identified the same issue I uncovered in my selectively toggling of rules. Thank you very much!
My problem was that the IP alias OpenDNSFamilyShieldServers are evaluated to the OpenDNS Family Shield servers 208.67.222.123 and 208.67.220.123, whereas in System → General Setup → DNS Server Settings I had 208.67.222.222 and 208.67.220.220. Those are the standard OpenDNS servers. With that mismatch my subnet could not access any DNS server.
The fix was changing System → General Setup → DNS Server Settings.
-
-