FreePBX | Register | Issues | Wiki | Portal | Support

Incorrect Subnet Mask on Sangoma Smart Firewall Interface

freepbx
Tags: #<Tag:0x00007f74a69960e8>

(Herbw) #1

After installing freepbx 14 / asterisk 13, I enabled the Sangoma Smart Firewall. My workstation is on my DMZ, which has a subnet mask of 255.255.255.240 (/28). However, the Firewall Interfaces GUI shows this as a Trusted Interface with a /24 Subnet Mask. This is incorrect and dangerous, as it would treat some outside hosts as trusted. I can not find any way to correct this Subnet Mask.

fwconsole firewall list trusted does not show this rule.

From the command line, I tried:
fwconsole firewall stop
fwconsole firewall untrust xxx.xxx.xxx.xxx/24
fwconsole firewall trust xxx.xxx.xxx.xxx/28
fwconsole firewall start

but this did not resolve the problem. My Networks tab now shows the correct rule, but my Interfaces tab still shows the INCORRECT rule.

How can I get rid of this incorrect interface definition?


(Lorne Gaetz) #2

AFAIK, Firewall just pulls the interface directly from the OS. What is the subnet mask showing in ifconfig?


(Herbw) #3

Thanks, Lorne. That was the problem, and it’s fixed now.

For what it’s worth, I did manually configure the interface, including the subnet mask, gateway, and DNS servers during the installation process. IP address, gateway, and DNS servers were all correct, but subnet mask somehow got lost.


(system) closed #4

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.