• February 23, 2025, 03:38:37 PM
  • Welcome, Guest
Please login or register.

Login with username, password and session length
Advanced search  

News:

This Forum Beta is ONLY for registered owners of D-Link products in the USA for which we have created boards at this time.

Pages: 1 [2]

Author Topic: Problems with access control and blocking SSL to only some MACs  (Read 20842 times)

bbear

  • Level 1 Member
  • *
  • Posts: 24
Re: Problems with access control and blocking SSL to only some MACs
« Reply #15 on: February 06, 2012, 08:05:35 PM »

I created a DHCP reservation for every single device in my household. I created two access rules from scratch, one for the Block list and one for the Exception list, however this time instead of referencing the MAC addresses I used the IP. Note that like before, not all of the IPs were available via that Machine Name pull-down so I just typed the address in by hand.

Result: Same issue as before, i.e. when I enable the Block rule, everything on my home network looses access to the internet, even the computers which appear in the Exceptions rule.

I don't know what else to try, I am wondering now if I have something fundamentally wrong with the way I have set up the rules. Here is an overview of the rules which I have set:

The first rule (named: 'SslBlock') is set up as follows:

  Filtering=Block some access
  Logged=No
  Schedule=StudyTime (5pm to 9pm weekdays)
  IP address ending in 21
  IP address ending in 22
  IP address ending in 25
  Apply Web Filter
  Advanced Port Filters

The advanced port filter is set up for the full IP range, Port 443, UDP protocol


The second rule (named 'Exceptions_1') is set up as follows:

  Filtering=Log web access only
  Logged=yes
  Schedule=Always
  IP address ending in 20
  IP address ending in 23
  IP address ending in 24
  IP address ending in 26
  IP address ending in 30

IP ending in 20 is the administrator PC

Can you think of anything wrong with the rules which I have set?
Logged

FurryNutz

  • Poweruser
  •   ▲
    ▲ ▲
  • *****
  • Posts: 49923
  • D-Link Global Forum Moderator
    • Router Troubleshooting
Re: Problems with access control and blocking SSL to only some MACs
« Reply #16 on: February 07, 2012, 07:04:23 AM »

Looks good...
What happens if you take out all manges devices and just set up the one MAC address that seems to cause the issue?
Logged
Cable: 1Gb/50Mb>NetGear CM1200>DIR-882>HP 24pt Gb Switch. COVR-1202/2202/3902,DIR-2660/80,3xDGL-4500s,DIR-LX1870,857,835,827,815,890L,880L,868L,836L,810L,685,657,3x655s,645,628,601,DNR-202L,DNS-345,DCS-933L,936L,960L and 8000LH.

bbear

  • Level 1 Member
  • *
  • Posts: 24
Re: Problems with access control and blocking SSL to only some MACs
« Reply #17 on: February 11, 2012, 09:25:58 AM »

Well, from my experiments today I am left totally confused, it is as if the whole access control thing is broken ..

This time I am starting with much the same set of IPs as before but for the Exceptions rule I changed it to use the same schedule (which at the moment should NOT be active as it is only defined for some weekdays, and it is Saturday today..

The first rule (named: 'SslBlock') is set up as follows:

  Filtering=Block some access
  Logged=No
  Schedule=StudyTime (5pm to 9pm weekdays)
  IP address ending in 21
  IP address ending in 22
  IP address ending in 25
  Apply Web Filter
  Advanced Port Filters

The advanced port filter is set up for the full IP range, Port 443, UDP protocol


The second rule (named 'Exceptions_1') is set up as follows:

  Filtering=Log web access only
  Logged=yes
  Schedule=StudyTime (5pm to 9pm weekdays)
  IP address ending in 20
  IP address ending in 23
  IP address ending in 24
  IP address ending in 26
  IP address ending in 30

IP ending in 20 is the administrator PC

The following is the sequence that I used in deleting the IP addresses from each of the rules. Whilst doing this I was pinging my ISP to check when I lost internet connection and when it came back:

Step 1) Starting IP setup (above), RESULT: No internet
Step 2) Remove IP ending in 21, RESULT: when hit the save button the router rebooted! Came back up with No internet
Step 3) Removed 22, RESULT: saved OK, No internet
Step 4) Removed 30, RESULT: saved OK, No internet
Step 5) Removed 26, RESULT: saved OK, No internet
Step 6) Removed 24, RESULT: saved OK, No internet
Step 7) Removed 23, RESULT: saved OK, No internet

So at this point my rules are basically:

'SslBlock':
   IP address ending in 25

'Exceptions_1':
    IP address ending in 30

And I still have no internet access!

Onto the next step ..

Step 8 Disabled the SslBlock rule, RESULT: Still no internet!
Step 9) Disabled the Exceptions_1, RESULT: Internet working again

At this point I haven't a clue what's going on, the access control/schedules seem to be following no logical pattern that I can determine
« Last Edit: February 12, 2012, 09:50:24 AM by bbear »
Logged

FurryNutz

  • Poweruser
  •   ▲
    ▲ ▲
  • *****
  • Posts: 49923
  • D-Link Global Forum Moderator
    • Router Troubleshooting
Re: Problems with access control and blocking SSL to only some MACs
« Reply #18 on: February 13, 2012, 06:56:34 AM »

Have you tried to just add one device per rule that you set up and test the rule out? If it works with one, then graduate to adding the next device.
Logged
Cable: 1Gb/50Mb>NetGear CM1200>DIR-882>HP 24pt Gb Switch. COVR-1202/2202/3902,DIR-2660/80,3xDGL-4500s,DIR-LX1870,857,835,827,815,890L,880L,868L,836L,810L,685,657,3x655s,645,628,601,DNR-202L,DNS-345,DCS-933L,936L,960L and 8000LH.

bbear

  • Level 1 Member
  • *
  • Posts: 24
Re: Problems with access control and blocking SSL to only some MACs
« Reply #19 on: February 14, 2012, 08:53:35 PM »

I did as you suggested, I set about creating two completely new rules ..

I started by creating the first rule (the blocking rule). As soon as I entered the UDP port start (443) and port end (443) and saved it, I lost connection to the internet. This was despite the following:

1. It was not within the time defined in the schedule I had applied to the rule
2. The computer I lost connection to the internet (the admin PC) was not the IP which the rule applied to

Is there something illegal which I am doing with the UDP port range or something?
Logged

FurryNutz

  • Poweruser
  •   ▲
    ▲ ▲
  • *****
  • Posts: 49923
  • D-Link Global Forum Moderator
    • Router Troubleshooting
Re: Problems with access control and blocking SSL to only some MACs
« Reply #20 on: February 16, 2012, 07:03:08 AM »

Suppose you don't have a another router to test this out on. I suppose I should break out my 825 and test this out. Sounds like it might be a illegal parameter or configuration possibly.
Logged
Cable: 1Gb/50Mb>NetGear CM1200>DIR-882>HP 24pt Gb Switch. COVR-1202/2202/3902,DIR-2660/80,3xDGL-4500s,DIR-LX1870,857,835,827,815,890L,880L,868L,836L,810L,685,657,3x655s,645,628,601,DNR-202L,DNS-345,DCS-933L,936L,960L and 8000LH.

bbear

  • Level 1 Member
  • *
  • Posts: 24
Re: Problems with access control and blocking SSL to only some MACs
« Reply #21 on: February 16, 2012, 10:32:57 AM »

Unfortunately I don't have any other router. Thanks for offering to try on your 825, do you want me to send you my saved config?
I have the config as I have it now, also I saved the config before I started adding the access rules
Logged

FurryNutz

  • Poweruser
  •   ▲
    ▲ ▲
  • *****
  • Posts: 49923
  • D-Link Global Forum Moderator
    • Router Troubleshooting
Re: Problems with access control and blocking SSL to only some MACs
« Reply #22 on: February 16, 2012, 10:38:01 AM »

Ya that would be great, since we have the same Rev router it should work. Just make sure you remove any WiFi and Admin log in passwords then save off the config file. You can email it to my address listed in my profile.

Also curious, does this happen if you use a different port? Something not 443?
Logged
Cable: 1Gb/50Mb>NetGear CM1200>DIR-882>HP 24pt Gb Switch. COVR-1202/2202/3902,DIR-2660/80,3xDGL-4500s,DIR-LX1870,857,835,827,815,890L,880L,868L,836L,810L,685,657,3x655s,645,628,601,DNR-202L,DNS-345,DCS-933L,936L,960L and 8000LH.

bbear

  • Level 1 Member
  • *
  • Posts: 24
Re: Problems with access control and blocking SSL to only some MACs
« Reply #23 on: March 11, 2012, 09:29:00 AM »

hello,

I was wondering if you have had a chance to test out my config on your DIR-825

thanks
Logged

FurryNutz

  • Poweruser
  •   ▲
    ▲ ▲
  • *****
  • Posts: 49923
  • D-Link Global Forum Moderator
    • Router Troubleshooting
Re: Problems with access control and blocking SSL to only some MACs
« Reply #24 on: March 12, 2012, 11:57:52 AM »

Hey Bear, Sorry I have been doing some other things with router lately. I do have your config file and have reviewed it. I'll go play with this after work today and see if I can reproduce this.  ;)
Logged
Cable: 1Gb/50Mb>NetGear CM1200>DIR-882>HP 24pt Gb Switch. COVR-1202/2202/3902,DIR-2660/80,3xDGL-4500s,DIR-LX1870,857,835,827,815,890L,880L,868L,836L,810L,685,657,3x655s,645,628,601,DNR-202L,DNS-345,DCS-933L,936L,960L and 8000LH.

FurryNutz

  • Poweruser
  •   ▲
    ▲ ▲
  • *****
  • Posts: 49923
  • D-Link Global Forum Moderator
    • Router Troubleshooting
Re: Problems with access control and blocking SSL to only some MACs
« Reply #25 on: March 12, 2012, 06:19:25 PM »

So I loaded it this evening and can't get in. Can you disable the graphical CAPTCHA and set the admin PW blank then save the config once more and email it to me.
Logged
Cable: 1Gb/50Mb>NetGear CM1200>DIR-882>HP 24pt Gb Switch. COVR-1202/2202/3902,DIR-2660/80,3xDGL-4500s,DIR-LX1870,857,835,827,815,890L,880L,868L,836L,810L,685,657,3x655s,645,628,601,DNR-202L,DNS-345,DCS-933L,936L,960L and 8000LH.
Pages: 1 [2]