Comments

5 comments

  • Avatar
    FirewallaSupportDesk

    Could you clarify what's the definition of rejecting and dropping? 

    Firewalla rules do block flows and you can find blocked flows on Box Main page. 

    0
    Comment actions Permalink
  • Avatar
    Thatdamnrainbow

    Dropping a packet - client doesn’t know what happened. It reached out for something, never heard back.
    Rejecting a packet - client is told no right away so it doesn’t keep asking the same thing over and over.

    0
    Comment actions Permalink
  • Avatar
    Dave

    Thatdamnrainbow is looking for ICMP Type 3 Code 13 response for UDP rule rejections and TCP RST for TCP rule rejections so that applications that support these responses can say they connection was refused. i.e. Chromium-based browsers would typically respond with a message saying "ERR_CONNECTION_REFUSED" or "ERR_CONNECTION_RESET" vs. traffic being silently dropped and leaving the application/user thinking there's a connection issue vs. a policy issue.

    0
    Comment actions Permalink
  • Avatar
    Thatdamnrainbow

    Basically a have a terribly configured work machine that guesses if it’s in the office or at home based on if it can reach certain IP addresses. Because the firewalla drops packets instead of rejecting them, it spends several minutes every day spinning its wheels with its stupid repeat attempts.

    it takes 4 minutes to accept a login password at home because the work PC doesn’t understand it needs to build its VPN tunnel without being rejected, so it keeps repeating until it’s failed for 4 minutes  

    IT won’t fix it, saying it’s my fault for having a “weird network with IP addresses starting at 10” so I need my firewalla to outright tell it no so it can move on.

    0
    Comment actions Permalink
  • Avatar
    FirewallaSupportDesk

    This is not a supported feature. You can post it in https://help.firewalla.com/hc/en-us/community/topics/115000356994-Feature-Requests- as a feature request instead. 

    While I don't know how exactly your work PC/Office network is configured, if you try to user a different IP range for Firewalla LAN, will it help? Such as using 192.168.x.0/24? 

    0
    Comment actions Permalink

Please sign in to leave a comment.