Got it

EG8245W5-6T Firewall Functions

Latest reply: Apr 20, 2022 12:13:53 52 1 1 0 0

Hello, everyone!

Today, I'd like to share a case with you.

Product Model: EG8245W5-6T


Problem Description


Users customize device firmware for ONT (EG8245W5-6T). After users upload device firmware, Internet services are interrupted continuously.


The ONT loses the connection to the public IP address and restores the connection to the public IP address only when the private IP address assigned to the Internet WAN is pinged.


Problem Analysis


The ONT LAN public IP address 186.x.x.245 and the IP address of the PC connected to the ONT cannot be accessed through the external network. Access is available only when the user pings the WAN IP address 10.x.x.14.


LAN Public-Network Host IP Address:

EG8245W5-6T


 WAN IP Address:

EG8245W5-6T


Cause analysis:


Collect one-click ONT information and device logs. During the information collection process, run the display firewall rule command to query the rules of the ONT IPv4/IPv6 firewall and specific links in the firewall indicates that the following problems are found:


1. By default, the firewall prohibits WAN-side packets from being sent to the LAN.

FWD_FIREWALL is located at the end of the forwarding chain. If there is no accept rule before FWD_FIREWALL, the packets on FWD_FIREWAL are discarded. As a result, the LAN-side public IP address cannot be pinged.


EG8245W5-6T


EG8245W5-6T


2. When pinging static WAN IP address 10.x.x.14 from the WAN side, the accept rule on the FWD_SERVICE chain can match because the session has been established. Use the same WAN when pinging the public IP address. The session is not aged and can match the acceptance rule. FWD_SERVICE is placed before FWD_FIRWALL and will not be discarded by the firewall.


EG8245W5-6T


Root Cause


By default, the firewall prohibits WAN-side packets from being sent to the LAN-side. FWD_FIREWALL is located at the end of the forwarding chain. If FWD_FIREWALL is not preceded by an acceptance rule, packets are discarded on FWD_FIREWAL. Therefore, the LAN-side public IP address cannot be pinged.


Solution Description


You can configure the IP filter trust list on the ONT web page to solve this problem.


EG8245W5-6T



Welcome to leave a message below.

We study together.

Thank you!

The post is synchronized to: Access Network Product Cases

Wow
Exellent!
View more
  • x
  • convention:

Comment

You need to log in to comment to the post Login | Register
Comment

Notice: To protect the legitimate rights and interests of you, the community, and third parties, do not release content that may bring legal risks to all parties, including but are not limited to the following:
  • Politically sensitive content
  • Content concerning pornography, gambling, and drug abuse
  • Content that may disclose or infringe upon others ' commercial secrets, intellectual properties, including trade marks, copyrights, and patents, and personal privacy
Do not share your account and password with others. All operations performed using your account will be regarded as your own actions and all consequences arising therefrom will be borne by you. For details, see " User Agreement."

My Followers

Login and enjoy all the member benefits

Login

Block
Are you sure to block this user?
Users on your blacklist cannot comment on your post,cannot mention you, cannot send you private messages.
Reminder
Please bind your phone number to obtain invitation bonus.