BLUE access with DD-WRT router not getting browser access

I have IPFIRE 182 router with 4-nics.
all 4-configured with R,G,B,O
Have separate dd-wrt router- tplink 1750 with dhcp enabled for wifi clients. rj45 from BLU nic to tplink WAN port.

: everything was working fine until Sat(03/02/24) morning.
: Lost all access to blue network.
: Initially had everything setup in FW and Blue access to perfection based on wiki.
: Therefore, I upgraded ddwrt tplink 1750 to latest firmware: Upgraded and performed 'reset to default" option after upgrade and rebooted.

Now, once connected to BLUE network, I can ping IP’s and perform dns lookups via nslookup.
But web access is “web page not found” otherwise NO browsing access.
NOTE:
A. DONE: Disable MAC Address filtering for ALL clients
B: DONE: 03/11 posting===> Firewall Rules for Blue <> Green - #3 by s8bordes

What did I miss? what cli command can i try? BTW, all green clients have no issues. Orange is not used. Please advise!

Additionally, this is a Qotom box with antenna. therefore i tried setting up hostapd with all the wiki tips.
Still same issue: no browser access

hostpad status is “running”
lspci does-not show wifi antenna (usb: IMC Networks) Wireless Lan Mini usb mini-card

I have also read this post too: I’m still on 182

I am not using pihol

Further clarification: blu nic on 192.168.180.0 network

  1. IPF router==blue nic(rj45)===> to wan port==> ddwrt-tplink router
  2. tplink rtr===>192.168.180.3==> static ip (local ip)
    -----> WAN Conn= disabled
  3. Laptop via rj45 (static ip on 180 net seq. ===> direct to tplnk-SW Port1
  4. ping, dig, nslookup works fine
  5. Cannot browse websites.
  6. Not using nor configured wifi settings. just direct rj45.

Please advise!

i got it working after 3-days.
solution:

Per ABelka: deleted all fw rules, blue config. and removed blu transparency

redid FW rule, with blu cfg

a. In IPF/FW/Blue access
b. added the ddwrt (network-setup{local IIP AND mac address
c. added the FULL subnet block 180.0/24 w/o mac
d. ran a squid stop-flush-restart
e. added FW rule source==>BLU “no nat”
f. Dest(std) = GRN w/ proto TCP
g : ddwrt is giving out ip’s
h. Network/WebProxy/NetbasedAccessCTRL= add 180 subnet block
i. and voila.

I gave full FW rules stated so that someone can correct me if its wrong…

I rebooted the ddwrt and IPF to make sure.
Hope this may help others.

OKAY…I spoke too soon.
HAD power outage today(Mar10) around 12:00pm GMT

rebooted IP fire…cannot browse from blue ; nslookup/dig/whois/tracepath works; however, curl ipecho.net/plain; echo <===does NOT resolv **

(curl: (7) Failed to connect to ipecho.net port 80: Connection timed out)

**

IPF SETUP: dd-wrt router as AP
gR= 170.1 180.3
blue:180.1
or= 160.1
I am able to get browse from all workstations on 170 .0
I am able to connect to wifi router SSID, BUT NO BROWSE ACCESS

turned off web proxy blue, all firewall rules and DELETED blue wireless config and rebooted ipfire
rebooted ddwrt router
shutdown-restart ddwrt router

PLZ see screenshots! from what is gleaned from ipfire wiki, only 2,3&4 are necessary for blue to browse internet.
the only thing not done is “reset” ddwrt and re-import backup file.




![image|426x500](upload://xlGfS0l6vWmvzEOhuVRhNiKqsmV

.png)

I have NEVER-EVER had this much difficulty.

What am i missing? Everyone/Any1/Sum1 please advise!

Check your IPFire Domain dame system for errors.

With Blue Access disabled you should need no firewall rules to reach RED.

2 Likes

https://www.ipfire.org/docs/configuration/firewall/accesstoblue#trouble

Hi…unsure what you mean?Plz elaborate? proxy BLU is on

BLU is on 180 subnet. Per the wiki, the only requirement for BLU to browse the net is:


REQUIRING NO FW RULES. Plz correct if its wrong.

Hi…no logs with

" Lots of Drop_Wirelessforward messages in the firewall log?

FYI, deleted all FW rules… this is still active:
image

no browse access. This is left “on”…

image

I also removed the web proxy on BLU…still no access
Deleted the “wireless config” and re-added…still no go…
Performed command:

/etc/rc.d/init.d/firewall restart && /etc/rc.d/init.d/squid restart

still no access.

Can my IPFIRE be corrupted? If-After a re-install, turning on web-proxy on blue and config. the wireless config page, w/o any FW rules, should provide connection to the AP? Is this statement true?

Therefore, Everyone/Any1/Sum1 please advise!

I’am I to take this as you have no internet access from Green?
this is a whole other problem.

If DDwrt is doing DHCP.
Can you connect a laptop to the IPFire Blue nic
will need to set laptop for manual IP
Does it reach the internet?

I have full internet access IN Green.

No internet when directly connected to the IPFire Blue nic.

Of course, i can ping GR, BL and OR.
?

What is the IP of your blue Nic.?
This is your gateway IP for clients in Blue.
PC in Blue
IP 192.168.180.7
Subnet ? 255.255.255.0
Gateway 192.168.180.1? Blue nic IP

BLUE= 180.1
had set laptop to : 192.168.180.100
SM: 255.255.255.0
GW: 192.168.180.1
dns: 192.168.180.1

There is a tab in the WUI
Firewall
Blue Access

Add 192.168.180.0/24
To disable Mac filter

1 Like

already done!
image

I also tried lan cable from IPF Blu nic to port-1 on wireless router switch. Still no access.

Please confirm this statement is TRUE!

**

If-After a re-install, turning on web-proxy on blue and the wireless config page, w/o any FW rules, should provide connection to the AP? Is this statement true?

**

A. Could IPFIRE sw is corrupt requiring re-install?
B. Could it be the HW devices: IPF and AP?

A or B is a possibility.
Or subnet is wrong.

1 Like

JUST TO UPDATE:

  • Re-installed IPF WITH 183.
  • same network config as posted above
  • BLUE web proxy ON
  • IPS on
    -started with isp dns
  • used this FW sequence (see screenshot)

basically the same as posted above and everything is fine.

I’m not sure why IPF got corrupted.
NOTE: originally i used several DNS from IPF wiki. Chk DNS server would show “OK”.

Therefore ?'s:
Is the current FW rules written to firewall.local?
The Blue config page- where is file written to?

Many thanks to Jon and Shaun!! FWIW, Since 2006, I have been using IPCOP with the migration to IPFIRE… this is my 5th re-install…