Forums

Skip to content

Advanced search
  • Quick links
    • Unanswered topics
    • Active topics
    • Search
  • FAQ
  • Login
  • Register
  • Board index Assistance Networking & Security
  • Search

SPI Firewall, security and trouble with DNS

Having problems getting connected to the internet or running a server? Wondering about securing your box? Ask here.
Post Reply
Advanced search
8 posts • Page 1 of 1
Author
Message
devsk
Advocate
Advocate
User avatar
Posts: 3039
Joined: Fri Oct 24, 2003 1:16 am
Location: Bay Area, CA

SPI Firewall, security and trouble with DNS

  • Quote

Post by devsk » Mon Jan 12, 2009 7:46 am

My router WGR614v5 has a built-in SPI firewall which analyzes incoming packets and blocks access. Now, the problem is that the processor on this thing is not fast enough and rules are weird. Its basically blocking replies to some valid DNS inquiries as well and dropping packets. I end up with firefox stuck in "looking up <blah>" on many pages. Konqueror almost always fails to load tabs with "unknown host" page.

Once I disable SPI firewall, I see no slowdowns in firefox, and konq works fine. My internet throughput (both up and down) improves A LOT! The router doesn't allow me to change any properties of the firewall. Its just enable/disable.

Now, the question is: Should I disable SPI firewall? I do get benefits of NAT from the router and have no open ports or DMZ. Is that enough? Or is the world not safe enough to leave SPI firewall disabled? What are your thoughts?

Is there a good router with good enough SPI firewall which works with DNS and VPN, can handle a bit of load, can be configured a little bit?
Top
Plumbo
n00b
n00b
Posts: 46
Joined: Fri Feb 01, 2008 11:35 pm

  • Quote

Post by Plumbo » Mon Jan 12, 2009 8:46 pm

I guess it all comes down to how paranoid you feel :)
Personally I would try to track down the source of the problems so that I could enable the firewall again. That shouldn't mean that you need to buy yourself another piece of hardware though.

Are you up to date on the firmware for your device? They usually release a couple of updates after some time, but alot of people just forget about updating it.
You could also consider looking at some alternatives like flashing it with dd-wrt or something, as that's known to be working very well with all supported hardware.
Check this site for compatibility and instructions if you want to check it out: http://www.dd-wrt.com/wiki/index.php/Supported_Devices
/Plumbo
Top
devsk
Advocate
Advocate
User avatar
Posts: 3039
Joined: Fri Oct 24, 2003 1:16 am
Location: Bay Area, CA

  • Quote

Post by devsk » Mon Jan 12, 2009 9:25 pm

I have the latest firmware for the router installed.

dd-wrt doesn't support wgr614v5....:(

I can try downgrading to earlier versions to see if the problem goes away with those but I am not sure if its safe. I don't want to end up with a brick.

The problem definitely is the SPI firewall because if I disable it, the problem goes away.
Top
Plumbo
n00b
n00b
Posts: 46
Joined: Fri Feb 01, 2008 11:35 pm

  • Quote

Post by Plumbo » Mon Jan 12, 2009 11:41 pm

Hmmm,,, I see others are having similar problems on another forum:
I also found that it has DNS lookup problems after switching between ISPs, which may be related to the problems others have reported with dynamic IP lease renewals. It appears to have updated the DNS addresses, but in fact DNS lookups can be unstable for a while after a switch, possibly due to an internal lookup cache not being cleared properly. It helps to specify the DNS addresses explicitly instead of relying on DHCP.
What kind of setup do you have for your ISP? Are you able to set the DNS adresses manually to see if that solves the issue?
/Plumbo
Top
devsk
Advocate
Advocate
User avatar
Posts: 3039
Joined: Fri Oct 24, 2003 1:16 am
Location: Bay Area, CA

  • Quote

Post by devsk » Tue Jan 13, 2009 1:51 am

I have tried everything. Manual ISP (comcast, for last 6 years) provided DNS servers in resolv.conf, 4.2.2.X series in resolv.conf, dnsmasq, named from bind. But everything ultimately gets stuck behind DNS from router because cache expires.

And its not just about DNS. I think in general the router is slow when SPI is enabled. I think its internal processor is not able to keep up with packet inspection when there is large barrage of packets. Not to mention it might detecting some of that as DOS.
Top
Hu
Administrator
Administrator
Posts: 24398
Joined: Tue Mar 06, 2007 5:38 am

  • Quote

Post by Hu » Tue Jan 13, 2009 3:31 am

What systems are protected by this router? If it is only shielding Linux hosts, I would turn off the router's firewall and use a packet filter on the Linux host. Linux can do stateful inspection of incoming traffic, and I would be surprised if Linux cannot match the router's features. If you have some other type of machine behind the router, particularly a Windows one, it is a harder decision. Theoretically, having it doing NAT should protect the internal hosts by virtue of it dropping incoming probes due to it not being able to map them to a specific machine.
Top
devsk
Advocate
Advocate
User avatar
Posts: 3039
Joined: Fri Oct 24, 2003 1:16 am
Location: Bay Area, CA

  • Quote

Post by devsk » Tue Jan 13, 2009 7:04 am

Hu wrote:What systems are protected by this router? If it is only shielding Linux hosts, I would turn off the router's firewall and use a packet filter on the Linux host. Linux can do stateful inspection of incoming traffic, and I would be surprised if Linux cannot match the router's features. If you have some other type of machine behind the router, particularly a Windows one, it is a harder decision. Theoretically, having it doing NAT should protect the internal hosts by virtue of it dropping incoming probes due to it not being able to map them to a specific machine.
Yeah, it is serving a mix of Windows and Linux hosts.
Top
minor_prophets
Apprentice
Apprentice
Posts: 281
Joined: Sun Oct 07, 2007 9:25 pm

  • Quote

Post by minor_prophets » Tue Jan 13, 2009 8:41 pm

Will Tomato run on that router, I wonder.

I am running 2 wrt54g's w/ dd-wrt. I'm not thrilled. Definitely beats the crappy stock firmware from Linksys. I'm at the point now where I would rather build my own. I'm currently awaiting a CF-to-IDE attachment and a 3-GB lan daughtercard for one of those Jetway C7 1.2Ghz fanless jobers.

I'm just trying to sort out whether I'll be running netfilter or pf, CF card only and/or use a 2.5" sata drive I have.
Top
Post Reply

8 posts • Page 1 of 1

Return to “Networking & Security”

Jump to
  • Assistance
  • ↳   News & Announcements
  • ↳   Frequently Asked Questions
  • ↳   Installing Gentoo
  • ↳   Multimedia
  • ↳   Desktop Environments
  • ↳   Networking & Security
  • ↳   Kernel & Hardware
  • ↳   Portage & Programming
  • ↳   Gamers & Players
  • ↳   Other Things Gentoo
  • ↳   Unsupported Software
  • Discussion & Documentation
  • ↳   Documentation, Tips & Tricks
  • ↳   Gentoo Chat
  • ↳   Gentoo Forums Feedback
  • ↳   Duplicate Threads
  • International Gentoo Users
  • ↳   中文 (Chinese)
  • ↳   Dutch
  • ↳   Finnish
  • ↳   French
  • ↳   Deutsches Forum (German)
  • ↳   Diskussionsforum
  • ↳   Deutsche Dokumentation
  • ↳   Greek
  • ↳   Forum italiano (Italian)
  • ↳   Forum di discussione italiano
  • ↳   Risorse italiane (documentazione e tools)
  • ↳   Polskie forum (Polish)
  • ↳   Instalacja i sprzęt
  • ↳   Polish OTW
  • ↳   Portuguese
  • ↳   Documentação, Ferramentas e Dicas
  • ↳   Russian
  • ↳   Scandinavian
  • ↳   Spanish
  • ↳   Other Languages
  • Architectures & Platforms
  • ↳   Gentoo on ARM
  • ↳   Gentoo on PPC
  • ↳   Gentoo on Sparc
  • ↳   Gentoo on Alternative Architectures
  • ↳   Gentoo on AMD64
  • ↳   Gentoo for Mac OS X (Portage for Mac OS X)
  • Board index
  • All times are UTC
  • Delete cookies

© 2001–2026 Gentoo Foundation, Inc.

Powered by phpBB® Forum Software © phpBB Limited

Privacy Policy

 

 

magic