reject instead of drop
Is there a way to create a rule that will explicitly reject traffic rather than dropping it?
-
Thatdamnrainbow is looking for ICMP Type 3 Code 13 response for UDP rule rejections and TCP RST for TCP rule rejections so that applications that support these responses can say they connection was refused. i.e. Chromium-based browsers would typically respond with a message saying "ERR_CONNECTION_REFUSED" or "ERR_CONNECTION_RESET" vs. traffic being silently dropped and leaving the application/user thinking there's a connection issue vs. a policy issue.
-
Basically a have a terribly configured work machine that guesses if it’s in the office or at home based on if it can reach certain IP addresses. Because the firewalla drops packets instead of rejecting them, it spends several minutes every day spinning its wheels with its stupid repeat attempts.
it takes 4 minutes to accept a login password at home because the work PC doesn’t understand it needs to build its VPN tunnel without being rejected, so it keeps repeating until it’s failed for 4 minutes
IT won’t fix it, saying it’s my fault for having a “weird network with IP addresses starting at 10” so I need my firewalla to outright tell it no so it can move on.
-
This is not a supported feature. You can post it in https://help.firewalla.com/hc/en-us/community/topics/115000356994-Feature-Requests- as a feature request instead.
While I don't know how exactly your work PC/Office network is configured, if you try to user a different IP range for Firewalla LAN, will it help? Such as using 192.168.x.0/24?
Please sign in to leave a comment.
Comments
5 comments