Hello,
I’m facing a strange issue:
- I have a successful ping to one public IP address
- When i execute a telnet command to this address and specify a port - the telnet is unsuccessful and the ping is stopping.
- The ping is coming back after a while - few minutes.
That’s the rules I have, while many of them are disabled to see is this a problem with firewall rules or not…
add action=accept chain=input dst-port=8291 protocol=tcp
add action=accept chain=input dst-port=8080 protocol=tcp
add action=accept chain=input protocol=icmp
add action=accept chain=forward dst-address=172.16.0.0/24 src-address=192.168.60.0/24
add action=accept chain=forward dst-address=192.168.60.0/24 src-address=172.16.0.0/24
add action=accept chain=input src-address=94.72.159.218
add action=accept chain=input src-address=94.72.159.220
add action=accept chain=forward connection-state=""
add action=accept chain=input comment="default configuration" connection-state=related
add action=accept chain=output connection-state=established,related disabled=yes
add action=drop chain=forward dst-address=192.168.60.0/24 src-address=192.168.199.0/24
add action=drop chain=forward dst-address=172.16.0.0/16 src-address=192.168.199.0/24
add action=drop chain=input disabled=yes dst-port=53 in-interface=ether1-gateway protocol=udp
add action=drop chain=input disabled=yes dst-port=53 in-interface=ether2-gateway protocol=udp
add action=drop chain=input disabled=yes dst-port=53 in-interface=ether2-gateway protocol=tcp
add action=accept chain=input dst-port=80 protocol=tcp
add action=drop chain=input comment="DROP API brutforce" disabled=yes dst-port=8728 protocol=tcp \
src-address-list=API_blacklist
add action=add-src-to-address-list address-list=API_blacklist address-list-timeout=30m chain=input \
connection-state=new disabled=yes dst-port=8728 protocol=tcp src-address-list=API_stage3
add action=add-src-to-address-list address-list=API_stage3 address-list-timeout=1m chain=input \
connection-state=new disabled=yes dst-port=8728 protocol=tcp src-address-list=API_stage2
add action=add-src-to-address-list address-list=API_stage2 address-list-timeout=1m chain=input \
connection-state=new disabled=yes dst-port=8728 protocol=tcp src-address-list=API_stage1
add action=add-src-to-address-list address-list=API_stage1 address-list-timeout=1m chain=input \
connection-state=new disabled=yes dst-port=8728 protocol=tcp
add action=drop chain=input comment="Drop SSH brutforce" disabled=yes dst-port=22 protocol=tcp \
src-address-list=ssh_blacklist
add action=add-src-to-address-list address-list=ssh_blacklist address-list-timeout=30m chain=input \
connection-state=new disabled=yes dst-port=22 protocol=tcp src-address-list=ssh_stage3
add action=add-src-to-address-list address-list=ssh_stage3 address-list-timeout=1m chain=input \
connection-state=new disabled=yes dst-port=22 protocol=tcp src-address-list=ssh_stage2
add action=add-src-to-address-list address-list=ssh_stage2 address-list-timeout=1m chain=input \
connection-state=new disabled=yes dst-port=22 protocol=tcp src-address-list=ssh_stage1
add action=add-src-to-address-list address-list=ssh_stage1 address-list-timeout=1m chain=input \
connection-state=new disabled=yes dst-port=22 protocol=tcp
add action=drop chain=input comment="DROP Telnet brutforce" disabled=yes dst-port=23 protocol=tcp \
src-address-list=telnet_blacklist
add action=add-src-to-address-list address-list=telnet_blacklist address-list-timeout=30m chain=\
input connection-state=new disabled=yes dst-port=23 protocol=tcp src-address-list=telnet_stage3
add action=add-src-to-address-list address-list=telnet_stage3 address-list-timeout=1m chain=input \
connection-state=new disabled=yes dst-port=23 protocol=tcp src-address-list=telnet_stage2
add action=add-src-to-address-list address-list=telnet_stage2 address-list-timeout=1m chain=input \
connection-state=new disabled=yes dst-port=23 protocol=tcp src-address-list=telnet_stage1
add action=add-src-to-address-list address-list=telnet_stage1 address-list-timeout=1m chain=input \
connection-state=new disabled=yes dst-port=23 protocol=tcp
add action=add-src-to-address-list address-list=port_scanners address-list-timeout=2w chain=input \
comment="Port scanners to list" disabled=yes protocol=tcp psd=21,3s,3,1
add action=add-src-to-address-list address-list=port_scanners address-list-timeout=2w chain=input \
comment="NMAP FIN Stealth scan" disabled=yes protocol=tcp tcp-flags=\
fin,!syn,!rst,!psh,!ack,!urg
add action=add-src-to-address-list address-list=port_scanners address-list-timeout=2w chain=input \
comment="SYN/FIN scan" disabled=yes protocol=tcp tcp-flags=fin,syn
add action=add-src-to-address-list address-list=port_scanners address-list-timeout=2w chain=input \
comment="SYN/RST scan" disabled=yes protocol=tcp tcp-flags=syn,rst
add action=add-src-to-address-list address-list=port_scanners address-list-timeout=2w chain=input \
comment="FIN/PSH/URG scan" disabled=yes protocol=tcp tcp-flags=fin,psh,urg,!syn,!rst,!ack
add action=add-src-to-address-list address-list=port_scanners address-list-timeout=2w chain=input \
comment="NMAP NULL scan" disabled=yes protocol=tcp tcp-flags=!fin,!syn,!rst,!psh,!ack,!urg
add action=drop chain=input comment="dropping port scanners" disabled=yes src-address-list=\
port_scanners
add action=drop chain=input comment="default configuration" disabled=yes in-interface=\
ether1-gateway
add action=drop chain=input disabled=yes in-interface=ether2-gateway
add action=drop chain=forward comment="default configuration" connection-state=invalid disabled=yes