Inactive Firewall?

Use this forum to post questions relating to WinGate, feature requests, technical or configuration problems

Moderator: Qbik Staff

Inactive Firewall?

Postby johnd » Feb 29 04 5:02 am

Hi,

I've just installed an evaluation copy of WinGate 5.2.3 on Windows 2003 Server.

Everything seems fine, except the firewall, which doesn't seem to be working at all. I've tried various security scans that can be initiated from Sygate's web site, and the scans are all reporting that the computer's ports are accessible - every single port they scan. Nothing at all is being written to the firewall log.

I've tried the high security option, and also the custom level, with ports explicitly blocked via the Port Security tab, but to no avail. The ports appear to be completely wide open.

Could you advise please?
Cheers
John
johnd
 
Posts: 17
Joined: Feb 29 04 4:42 am

Postby adrien » Feb 29 04 7:48 pm

Check that the interface settings are correct in GateKeeper under Options->Advanced->Network Interfaces.

This determines which is a trusted or untrusted interface, correlating to whether the "connections from the internet" rules are applied, or whether the connections are deemed to be from your local LAN.

Adrien
adrien
Qbik Staff
 
Posts: 5448
Joined: Sep 03 03 2:54 pm
Location: Auckland

Postby johnd » Feb 29 04 11:09 pm

Hi Adrien,

It has the "Interface is visible from the internet..." option ticked.
Cheers
John
johnd
 
Posts: 17
Joined: Feb 29 04 4:42 am

Postby adrien » Mar 01 04 3:18 am

Hi

what type of connection are you using?

This isn't an ethernet connection to a PPPoE modem is it?

In some cases with those setups, there are 2 IP interfaces on the same physical one, and if you have one IP set as internal, and one external but they are the same NIC then there could be a problem.

Adrien
adrien
Qbik Staff
 
Posts: 5448
Joined: Sep 03 03 2:54 pm
Location: Auckland

Postby johnd » Mar 01 04 4:00 am

It's a USB connection to a broadband modem. If I look at the Network Interfaces, I see:

192.168.0.1 - public=no, trusted=yes (with an NIC icon)
127.0.0.1 - public=no, trusted=yes (with a loopback icon)
Broadband - public=yes, trusted=no (with a telephone icon)
Cheers
John
johnd
 
Posts: 17
Joined: Feb 29 04 4:42 am

Postby johnd » Mar 02 04 7:05 am

I know these things can be tricky to diagnose at a distance, but do you think this is something we will be able to resolve? I'm keen to make a decision on our choice of proxy, and would like to recommend WinGate if the firewall issue can be sorted out.
Cheers
John
johnd
 
Posts: 17
Joined: Feb 29 04 4:42 am

Postby genie » Mar 02 04 9:09 am

Hi,
At the moment our testing lab is trying to reproduce this behavior - we'll let you know as we find (or not) anything that might manifest such behavior.
genie
Qbik Staff
 
Posts: 1788
Joined: Sep 30 03 10:29 am

Postby johnd » Mar 02 04 9:51 am

OK, thanks. Keep me posted.
Cheers
John
johnd
 
Posts: 17
Joined: Feb 29 04 4:42 am

Postby genie » Mar 02 04 10:32 am

Right, John, mjust got the results back - our testers did not find anything suspicious about running port scanners from behind the firewall - all hits were reported and the scanners had all the ports either stealth or closed.
There are a couple of things we can do right now:
- Make sure your firewall is set up correctly (security level is high/custom, unused ports are closed for the Internet-originated connections, interfaces are set up properly in terms of trusted/public relations.

- Drop me an email with your IP address so I can try scanning your machine from my side to see who replies - we found, for example, that some ISPs redirect HTTP requests through their internal proxies making online port scanners scan the ISPs gateway machines rather than your machine.
genie
Qbik Staff
 
Posts: 1788
Joined: Sep 30 03 10:29 am


Return to WinGate

Who is online

Users browsing this forum: No registered users and 2 guests

cron