• February 23, 2025, 04:20:49 PM
  • Welcome, Guest
Please login or register.

Login with username, password and session length
Advanced search  

News:

This Forum Beta is ONLY for registered owners of D-Link products in the USA for which we have created boards at this time.

Pages: [1] 2

Author Topic: Help needed with DFL-210  (Read 14546 times)

Carlos Oviedo

  • Level 1 Member
  • *
  • Posts: 7
Help needed with DFL-210
« on: June 16, 2010, 10:05:51 AM »

Sorry, but my english is so bad.

After i finish the Configuration Wizard on my Dfl-210, can`t access the internet.

What rules need to create or change?

Wan is in DHCP mode, and the ADSL is working fine, I have a wireless router conected and erverythig is ok.

I have a Windows 2003 server for the DHCP, so the DHCP service on the firewall is disabled.

Thanks.
« Last Edit: June 16, 2010, 10:08:59 AM by Carlos Oviedo »
Logged

Fatman

  • Level 9 Member
  • ****
  • Posts: 1675
Re: Help needed with DFL-210
« Reply #1 on: June 16, 2010, 10:21:54 AM »

Do you get a WAN IP?

If so what is the first 2 octets?

What IP information (IP Subnet Gateway DNS etc...) does the PC that is not getting on-line have?

Is that IP static or DHCP assigned?
Logged
non progredi est regredi

Carlos Oviedo

  • Level 1 Member
  • *
  • Posts: 7
Re: Help needed with DFL-210
« Reply #2 on: June 16, 2010, 10:32:14 AM »

1- Yes i get a WAN IP 201.199.X.X
2- The PC I`m using have an static IP 192.168.1.2, subnet 255.255.255.0, gateway 192.168.1.1, DNS 200.91.75.5/6
3- Later I will change the lan interface and lannet to the segments 192.168.0.X for compatibility with the internal network, but my intention was to make first the necesary test with the firewall.
Logged

Fatman

  • Level 9 Member
  • ****
  • Posts: 1675
Re: Help needed with DFL-210
« Reply #3 on: June 16, 2010, 10:56:07 AM »

Well in that case the wizard should have gotten you through.  Any log entries?
Logged
non progredi est regredi

Carlos Oviedo

  • Level 1 Member
  • *
  • Posts: 7
Re: Help needed with DFL-210
« Reply #4 on: June 16, 2010, 12:04:06 PM »

I just reset to factory defaults.
Erase al loging related to the new configuration.
Try to acces a web page and this are the 4 resulting log entries:

Severity: Warning
Category/ID: Rule/6000051
Rule: Default Rule
Proto: UDP
Src/DestIF: Lan
Src/DestIP: 192.168.1.2/192.168.1.1
Src/DestPort: 2792/53
Event/Action: ruleset_drop_packet/drop
Logged

danilovav

  • Level 4 Member
  • ****
  • Posts: 424
  • Alexandr Danilov
Re: Help needed with DFL-210
« Reply #5 on: June 16, 2010, 12:08:25 PM »

Set up external DNS server on your client (ex, 8.8.8.8 and 8.8.4.4) or configure DNS relay:
SAT lan/lannet core/lan_ip dns-all (SAT: new desination = wan_dns1)
NAT lan/lannet core/lan_ip dns-all
Logged
BR, Alexandr Danilov

Carlos Oviedo

  • Level 1 Member
  • *
  • Posts: 7
Re: Help needed with DFL-210
« Reply #6 on: June 16, 2010, 12:31:55 PM »

I configure DNS Relay but have no efect, no internet acess.

Maybe this is important, when I try to ping from the pc to the wan IP in the firewall I have no response.
The traffice betwen them is being blocked.
« Last Edit: June 16, 2010, 02:03:15 PM by Carlos Oviedo »
Logged

danilovav

  • Level 4 Member
  • ****
  • Posts: 424
  • Alexandr Danilov
Re: Help needed with DFL-210
« Reply #7 on: June 16, 2010, 07:53:16 PM »

By default, DFL has much disallowed. To allow LAN -> WAN ip ping, make rule Allow lan/lannet core/wan_ip ping-inbound. But it's not related with internet at all.
Logged
BR, Alexandr Danilov

Carlos Oviedo

  • Level 1 Member
  • *
  • Posts: 7
Re: Help needed with DFL-210
« Reply #8 on: June 28, 2010, 06:03:41 PM »

No way, i tried everything and can't access the internet. ???

Please give me an example of necesary IP rules. ;D
Logged

danilovav

  • Level 4 Member
  • ****
  • Posts: 424
  • Alexandr Danilov
Re: Help needed with DFL-210
« Reply #9 on: June 28, 2010, 08:15:33 PM »

Just try to ping everything (ex, 8.8.8.8) in internet by IP - is it working?
Logged
BR, Alexandr Danilov

chechito

  • Level 3 Member
  • ***
  • Posts: 193
Re: Help needed with DFL-210
« Reply #10 on: June 29, 2010, 05:52:47 AM »

how you connect to internet, if you connect a pc directly to the isp ???

Its important to have all the config information to connect to the isp, one good way to get this information its connecting a pc directly to the isp and take note of the configuration what gives you navigation.

es importante tener clara la configuración que debe tener la wan del firewall, una buena manera de averiguarlo es conectando un pc directamente al servicio de internet y observando la configuración con la cual logra navegar.

Logged

Carlos Oviedo

  • Level 1 Member
  • *
  • Posts: 7
Re: Help needed with DFL-210
« Reply #11 on: June 30, 2010, 01:11:11 PM »

The IP is DHCP assigned by the ADSL Modem.
The ADSL moden have 4 ports, all of them are working fine.
I have connected a D-Link DI-604 Router, a Wireless Router and the DFL-210 Firewall.
The DI-604 give access to the internet and is the one I want to change.

The configuration that the ADSL modem gives to the DFL-210 Firewall is the same that the DI-604 Router, only changes the IP.

I have a PC connected directly to the DFL-210 with the configuration indicated by the guide and the firewall have his default configuration.

PC:
IP 192.168.1.2
Sub 25.255.255.0
Gateway 192.168.1.1

 :'(
Logged

danilovav

  • Level 4 Member
  • ****
  • Posts: 424
  • Alexandr Danilov
Re: Help needed with DFL-210
« Reply #12 on: July 01, 2010, 12:58:07 AM »

If u have default configuration, specify on client's PCs external (ex, ISP) DNS servers and it should work.
Logged
BR, Alexandr Danilov

Carlos Oviedo

  • Level 1 Member
  • *
  • Posts: 7
Re: Help needed with DFL-210
« Reply #13 on: July 02, 2010, 02:44:10 PM »

it should work, but does'nt.
Please give me an example of necesary IP rules. Grin
« Last Edit: July 02, 2010, 02:46:34 PM by Carlos Oviedo »
Logged

danilovav

  • Level 4 Member
  • ****
  • Posts: 424
  • Alexandr Danilov
Re: Help needed with DFL-210
« Reply #14 on: July 02, 2010, 11:31:04 PM »

In minimal case, you need just one rule
NAT lan/lannet wan/all-nets all_services
Try to ping from client to 8.8.8.8 (Google DNS) and check in Status > Connections
And shouw your Status > Routes
Logged
BR, Alexandr Danilov
Pages: [1] 2