D-Link Forums

The Graveyard - Products No Longer Supported => Routers / COVR => DIR-655 => Topic started by: Ceram on November 28, 2008, 12:14:28 PM

Title: Whishlist for new firmware
Post by: Ceram on November 28, 2008, 12:14:28 PM
Is it possible to add the functionality of bandwith limiting based on Mac adresses? I want to limit kids bandwith use olso combined with a scedule.
Title: Re: Whishlist for new firmware
Post by: Sam on December 03, 2008, 01:18:27 AM
+1

Simple bandwidth control on port/level ip level/mac

ie. 192.168.0.1 is limited to 1Mbps
ie. port 1352 can use max 25% of available WAN bandwitdh.

Title: Re: Whishlist for new firmware
Post by: EddieZ on December 03, 2008, 06:19:14 AM
Requested:

1.        IPv6 support (firmware, all revisions)

2.        NAT Port Mapping Protocol



Title: Re: Whishlist for new firmware
Post by: tiagomiguel on December 03, 2008, 09:49:39 AM
That it works . lol
Title: Re: Whishlist for new firmware
Post by: twk3 on December 08, 2008, 01:41:19 PM
Stealth port 113 instead of just reporting it as open or closed. (Or did I miss a setting?)
Title: Re: Whishlist for new firmware
Post by: EddieZ on December 08, 2008, 02:45:52 PM
Stealth is a greater security risk then a closed port... Closed port: "darn, it says it cannot be openend", stealth: "hey, live IP but no respons...stealth, let's have a look at that."
Title: Re: Whishlist for new firmware
Post by: twk3 on December 10, 2008, 10:36:16 AM
Yes... but reporting as open is an even bigger security risk. Which is what it is being reported as at the moment. The latest versions of things like dd-wrt now stealth this port, setting it up so only an IP with an active session with a node behind the router can use it. I would say that is better than reporting it as open.
Title: Re: Whishlist for new firmware
Post by: EddieZ on December 10, 2008, 11:02:04 AM
Yes... but reporting as open is an even bigger security risk. Which is what it is being reported as at the moment. The latest versions of things like dd-wrt now stealth this port, setting it up so only an IP with an active session with a node behind the router can use it. I would say that is better than reporting it as open.

Open door  ;)
Title: Re: Whishlist for new firmware
Post by: twk3 on December 10, 2008, 11:17:00 AM
yeah... I have 113 forwarded >_< which is why it is open... I would just rather it be stealthed like the rest of my forwarded ports.
Title: Re: Whishlist for new firmware
Post by: EddieZ on December 10, 2008, 01:42:33 PM
Here's where you will find the reason why the port isn't stealthed (and probably will never be on a router): http://www.grc.com/port_113.htm
Title: Re: Whishlist for new firmware
Post by: funchords on December 10, 2008, 06:33:01 PM
yeah... I have 113 forwarded >_< which is why it is open... I would just rather it be stealthed like the rest of my forwarded ports.
That doesn't make sense.  If you've forwarded the port, then the router is going to pass the packet through.  It's not responsible for a response. 

What does the DIR-655 do when it's not forwarded? 

It's an old trick, but if the DIR-655 is doing something you don't like, and you want a port to behave as stealthed, then forward it to a completely unused IP address in your LAN.  Incoming packets will simply go to that black hole.
Title: Re: Whishlist for new firmware
Post by: funchords on December 10, 2008, 06:36:06 PM
When possible, translate outgoing ICMP 3 responses and send them through the LAN. 
Title: Re: Whishlist for new firmware
Post by: twk3 on December 10, 2008, 08:19:17 PM
If I don't forward, the port is returned as being closed (the only port that returns anything but stealthed). If I forward, the port is returned as being open.

Quote from: http://www.grc.com/port_113.htm
UPDATE: The latest firmware update for the Linksys family of NAT routers has added an adaptive IDENT stealthing feature (though it is not enabled by default). So the Linksys routers will give you the best of both worlds. Bravo Linksys!

We tested the newest dd-wrt firmware about couple days ago on a different router, it also stealths it.

I am required to use identd, that is why I have this port forwarded.

I realize you can't just stealth the port, you have to do an adaptive stealth. ZoneAlarm, linksys and dd-wrt all have managed to do it.
Title: Re: Whishlist for new firmware
Post by: funchords on December 10, 2008, 11:17:15 PM
If I don't forward, the port is returned as being closed (the only port that returns anything but stealthed). If I forward, the port is returned as being open.
Thanks! I wasn't aware of that.
Title: Re: Whishlist for new firmware
Post by: dommysangiu on December 11, 2008, 12:37:46 AM
1) In VIRTUAL SERVER - PORT FORWARDING - NETWORK FILTER display the computer name next to the MAC/IP ADDRESS

2) when the MAC FILTER is ON create a selectable list of the MAC ADDRESS that  want to access the netwok but don't have the permission

Thanks.
Title: Re: Whishlist for new firmware
Post by: funchords on December 11, 2008, 06:58:03 PM
Forwarding by DHCP MAC address instead of by IP address (that way servers wouldn't need a Reservation or a static IP)

Accurate automatic uplink detection when the ISP uses upload PowerBoost.  (Currently, upload PowerBoost causes the device into thinking that there is more uplink bandwidth than there actually is available long-term.)

QoS method that allows users to take advantage of upload PowerBoost.  (Currently, users with PowerBoost ISPs who have set their uplink speed to reflect their long-term reliable bandwidth are speed limited)