• April 21, 2025, 12:53:05 AM
  • Welcome, Guest
Please login or register.

Login with username, password and session length
Advanced search  

News:

This Forum Beta is ONLY for registered owners of D-Link products in the USA for which we have created boards at this time.

Pages: [1] 2

Author Topic: Whishlist for new firmware  (Read 12252 times)

Ceram

  • Guest
Whishlist for new firmware
« on: November 28, 2008, 12:14:28 PM »

Is it possible to add the functionality of bandwith limiting based on Mac adresses? I want to limit kids bandwith use olso combined with a scedule.
Logged

Sam

  • Level 1 Member
  • *
  • Posts: 9
Re: Whishlist for new firmware
« Reply #1 on: December 03, 2008, 01:18:27 AM »

+1

Simple bandwidth control on port/level ip level/mac

ie. 192.168.0.1 is limited to 1Mbps
ie. port 1352 can use max 25% of available WAN bandwitdh.

Logged

EddieZ

  • Level 10 Member
  • *****
  • Posts: 2494
Re: Whishlist for new firmware
« Reply #2 on: December 03, 2008, 06:19:14 AM »

Requested:

1.        IPv6 support (firmware, all revisions)

2.        NAT Port Mapping Protocol



Logged
DIR-655 H/W: A2 FW: 1.33

tiagomiguel

  • Level 1 Member
  • *
  • Posts: 17
Re: Whishlist for new firmware
« Reply #3 on: December 03, 2008, 09:49:39 AM »

That it works . lol
Logged

twk3

  • Level 2 Member
  • **
  • Posts: 60
Re: Whishlist for new firmware
« Reply #4 on: December 08, 2008, 01:41:19 PM »

Stealth port 113 instead of just reporting it as open or closed. (Or did I miss a setting?)
Logged

EddieZ

  • Level 10 Member
  • *****
  • Posts: 2494
Re: Whishlist for new firmware
« Reply #5 on: December 08, 2008, 02:45:52 PM »

Stealth is a greater security risk then a closed port... Closed port: "darn, it says it cannot be openend", stealth: "hey, live IP but no respons...stealth, let's have a look at that."
Logged
DIR-655 H/W: A2 FW: 1.33

twk3

  • Level 2 Member
  • **
  • Posts: 60
Re: Whishlist for new firmware
« Reply #6 on: December 10, 2008, 10:36:16 AM »

Yes... but reporting as open is an even bigger security risk. Which is what it is being reported as at the moment. The latest versions of things like dd-wrt now stealth this port, setting it up so only an IP with an active session with a node behind the router can use it. I would say that is better than reporting it as open.
Logged

EddieZ

  • Level 10 Member
  • *****
  • Posts: 2494
Re: Whishlist for new firmware
« Reply #7 on: December 10, 2008, 11:02:04 AM »

Yes... but reporting as open is an even bigger security risk. Which is what it is being reported as at the moment. The latest versions of things like dd-wrt now stealth this port, setting it up so only an IP with an active session with a node behind the router can use it. I would say that is better than reporting it as open.

Open door  ;)
Logged
DIR-655 H/W: A2 FW: 1.33

twk3

  • Level 2 Member
  • **
  • Posts: 60
Re: Whishlist for new firmware
« Reply #8 on: December 10, 2008, 11:17:00 AM »

yeah... I have 113 forwarded >_< which is why it is open... I would just rather it be stealthed like the rest of my forwarded ports.
Logged

EddieZ

  • Level 10 Member
  • *****
  • Posts: 2494
Re: Whishlist for new firmware
« Reply #9 on: December 10, 2008, 01:42:33 PM »

Here's where you will find the reason why the port isn't stealthed (and probably will never be on a router): http://www.grc.com/port_113.htm
Logged
DIR-655 H/W: A2 FW: 1.33

funchords

  • Level 3 Member
  • ***
  • Posts: 296
Re: Whishlist for new firmware
« Reply #10 on: December 10, 2008, 06:33:01 PM »

yeah... I have 113 forwarded >_< which is why it is open... I would just rather it be stealthed like the rest of my forwarded ports.
That doesn't make sense.  If you've forwarded the port, then the router is going to pass the packet through.  It's not responsible for a response. 

What does the DIR-655 do when it's not forwarded? 

It's an old trick, but if the DIR-655 is doing something you don't like, and you want a port to behave as stealthed, then forward it to a completely unused IP address in your LAN.  Incoming packets will simply go to that black hole.
Logged

funchords

  • Level 3 Member
  • ***
  • Posts: 296
Re: Whishlist for new firmware
« Reply #11 on: December 10, 2008, 06:36:06 PM »

When possible, translate outgoing ICMP 3 responses and send them through the LAN. 
Logged

twk3

  • Level 2 Member
  • **
  • Posts: 60
Re: Whishlist for new firmware
« Reply #12 on: December 10, 2008, 08:19:17 PM »

If I don't forward, the port is returned as being closed (the only port that returns anything but stealthed). If I forward, the port is returned as being open.

Quote from: http://www.grc.com/port_113.htm
UPDATE: The latest firmware update for the Linksys family of NAT routers has added an adaptive IDENT stealthing feature (though it is not enabled by default). So the Linksys routers will give you the best of both worlds. Bravo Linksys!

We tested the newest dd-wrt firmware about couple days ago on a different router, it also stealths it.

I am required to use identd, that is why I have this port forwarded.

I realize you can't just stealth the port, you have to do an adaptive stealth. ZoneAlarm, linksys and dd-wrt all have managed to do it.
« Last Edit: December 10, 2008, 08:25:14 PM by twk3 »
Logged

funchords

  • Level 3 Member
  • ***
  • Posts: 296
Re: Whishlist for new firmware
« Reply #13 on: December 10, 2008, 11:17:15 PM »

If I don't forward, the port is returned as being closed (the only port that returns anything but stealthed). If I forward, the port is returned as being open.
Thanks! I wasn't aware of that.
Logged

dommysangiu

  • Level 1 Member
  • *
  • Posts: 2
Re: Whishlist for new firmware
« Reply #14 on: December 11, 2008, 12:37:46 AM »

1) In VIRTUAL SERVER - PORT FORWARDING - NETWORK FILTER display the computer name next to the MAC/IP ADDRESS

2) when the MAC FILTER is ON create a selectable list of the MAC ADDRESS that  want to access the netwok but don't have the permission

Thanks.
Logged
Pages: [1] 2