Unable to connect to OPT1 from LAN
-
A local firewall on the file server with a wrong range?
Tried turning it completely off and still couldn't connect.
It looks like smb doesn't work well across subnets. I'm okay with using FTP instead, but I'm not sure why FTP isn't working either.
-
are you having active or passive ftp?
Maybe you should try to create a rule in opt1
allow smb traffic from servers to lan subnet -
are you having active or passive ftp?
Whatever Filezilla defaults to. I didn't mess with any of the settings.
Maybe you should try to create a rule in opt1
allow smb traffic from servers to lan subnetHow would that work? What ports are you saying I should open?
-
Google has the answer. I almost had to find it twice
few ports and remember to read that tcp/udp 445 also. it's not in the box -
Google has the answer. I almost had to find it twice
few ports and remember to read that tcp/udp 445 also. it's not in the boxSince the LAN rule allows the traffic to OPT1, I'm assuming you mean I should open the port from the DMZ side. Do I really need it if I only want access from the LAN to OPT1?
I just tried opening 445 tcp/udp from the server to the LAN subnet and it doesn't seem to have had any effect. I still can't connect a windows share.
I ended up installing CopSSH, and that's working so far, but my transfer speeds are horrible.
-
SMB itself isn't the easiest traffic type to troubleshoot. Thats is the reason why to use opening ports from another interface also. and yes i do know what is the meaning of spi
-
SMB itself isn't the easiest traffic type to troubleshoot. Thats is the reason why to use opening ports from another interface also.
Well, like I said, I opened 445 tcp/udp from the server on OPT1 to LAN and I still can't connect from the LAN.
and yes i do know what is the meaning of spi
Huh?
-
spi = Stateful firewall should keep ports open some while if connection is from inbound of it.
Then i have to admit, i don't have a glue what is the problem on this
-
spi = Stateful firewall should keep ports open some while if connection is from inbound of it.
Then i have to admit, i don't have a glue what is the problem on this
Me either. We'll see how things go when I swap out my current box for the new one.
Honestly, it wouldn't be so bad if sftp wasn't so slow.
-
smb and ftp might need some more knowledge, try to use search. There is lot of discussion already in this forum
here is some info regarding SMB i'm in the proccess to allow file share between ubuntu and windows
through pfense
this might help on the ports to opennetbios- ns -137/tcp # NETBIOS Name Service
netbios- dgm -138/tcp # NETBIOS Datagram Service
netbios- ssn -139/tcp # NETBIOS Session Service
microsoft-ds -445/tcp #if you are using Active Directorysome other ports that might help
Ports 389/tcp For LDAP
port 445/tcp NETBOIS was move to 445 after 2000 (CIFS)
port 901/tcp for SWAT service (web gui to configure Samba)here is a link that i got most of the info i needed also there is a sample ip table
http://www.cyberciti.biz/tips/connecting-linux-unix-system-network-attached-storage-device.html
i know this doesn't have a sample for pfsense but you can get what rules to create from the ip tables