Discussion
They're brand new ones, firmware 6.01.00.12 - ended up using telnet to try connections to all the listening ports listed on the domain controller via netstat -a. 135 and 389 were fine, port 445 seemed to be blocked. Can't see anything about netbios under VPN policies/edit allthough that does ring a bell, sure I've seen that somewhere before. I Switched to OpenVPN in the end, worked first time. Oh well
k, bit more info - via telnet (after enabling via setup.cgi?todo=debug)
Different ~3 month old dg834 Firmware V4.01.06
No netbios option in VPN policy
Partial output of iptables -L
Chain FORWARD (policy DROP)
target prot opt source destination
DROP tcp -- 192.168.1.0/24 anywhere tcp dpt:445
DROP tcp -- anywhere 192.168.1.0/24 tcp dpt:445
DROP udp -- anywhere 192.168.1.0/24 multiport dports 137,138,139
DROP udp -- 192.168.1.0/24 anywhere multiport dports 137,138,139
DROP tcp -- anywhere 192.168.1.0/24 multiport dports 137,138,139
DROP tcp -- 192.168.1.0/24 anywhere multiport dports 137,138,139
So all F&P sharing is explicitly dropped here with no option to enable it that I can see
Another ~3 month old one has firmware v 3.xx and does have an option in vpn policies to enable netbios, however I just lost contact with it before I could pull the iptables list out of it... d'oh. Theres a job for the morning
All good fun...
Different ~3 month old dg834 Firmware V4.01.06
No netbios option in VPN policy
Partial output of iptables -L
Chain FORWARD (policy DROP)
target prot opt source destination
DROP tcp -- 192.168.1.0/24 anywhere tcp dpt:445
DROP tcp -- anywhere 192.168.1.0/24 tcp dpt:445
DROP udp -- anywhere 192.168.1.0/24 multiport dports 137,138,139
DROP udp -- 192.168.1.0/24 anywhere multiport dports 137,138,139
DROP tcp -- anywhere 192.168.1.0/24 multiport dports 137,138,139
DROP tcp -- 192.168.1.0/24 anywhere multiport dports 137,138,139
So all F&P sharing is explicitly dropped here with no option to enable it that I can see
Another ~3 month old one has firmware v 3.xx and does have an option in vpn policies to enable netbios, however I just lost contact with it before I could pull the iptables list out of it... d'oh. Theres a job for the morning
All good fun...
Edited by aldi on Tuesday 14th November 21:51
Gassing Station | Computers, Gadgets & Stuff | Top of Page | What's New | My Stuff