Welcome, Guest. Please login or register.
Did you miss your activation email?
May 25, 2013, 08:44:52 PM

Login with username, password and session length

664090 Posts
70638 Topics
145268 Members

Latest Member: DemonicDM

Search:     Advanced search | Tag Cloud
+  Welcome to the Comodo Forum
|-+  Security Products & Services
| |-+  Comodo Internet Security - CIS
| | |-+  Help - CIS
| | | |-+  Firewall Help - CIS
| | | | |-+  intranet broadcasting does not work [RESOLVED]
« previous next »
Pages: [1] Go Down Print
Author Topic: intranet broadcasting does not work [RESOLVED]  (Read 1365 times)
herbun
Newbie
*
Offline Offline

Posts: 6


« on: October 23, 2009, 09:31:38 AM »

hi,

I have a predefined policy that does the following:

allow tcp or udp in/out for ip
source and destination mask: 192.168.1.0 mask 255.255.255.0
source and destination port: any.

second rule below the first one: block ip in out source and destination any protocol any.

these rules are applied to all pcs in the network and should make sure that the intranet communication is working, but no internet access is allowed.

but broadcasting does not work, because any application that requires broadcasts does not work, meaning clients do not find a server. any idea what I did wrong?

help would be amazing since this is a problem I have had for a long time now.

thanks alot

herbun
« Last Edit: October 23, 2009, 11:02:27 AM by herbun » Logged
EricJH
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 16723



« Reply #1 on: October 23, 2009, 09:44:12 AM »

Isn't the local multicast zone the zone from 239.0.0.0.-239.255.255.255? Then you need to add a rule for that zone.

To see what IP addresses get blocked make sure that the block rule of the policy also logs when it blocks. Then the logs will inform you what IP address range you need to allow.
Logged

herbun
Newbie
*
Offline Offline

Posts: 6


« Reply #2 on: October 23, 2009, 11:01:28 AM »

in this case it was 255.255.255.255 according to the logs, and it does work. I guess this will be not a security risk since the broadcast will be only on the lan, of course including all subnets, right?

thanks for the fast answer and the tip!
Logged
Ronny
Product Translator
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 13188


Volunteer Moderator


« Reply #3 on: October 23, 2009, 12:23:07 PM »

Hi Herbun,

Broadcast get's send to either 192.168.1.255 (Directed Broadcast) or to 255.255.255.255 (Limited Broadcast).

For the 192.168.1.255 goes that the host part of the ip subnet will be set to .255 so if you used 172.16.0.0/16 then the broadcast would be send to 172.16.255.255.

What Eric is refering to is Multicast but for that you also need to allow the IGMP or CGMP to allow the host to register to the Multicast groups.
Logged

Volunteer Moderator
Any concerns? Please send me a PM or review the Forum Policy -  update Jan 3rd 2013!
Tags:
Pages: [1] Go Up Print 
« previous next »
Jump to:  

SSL Certificate Free Virus Removal Firewall
Page created in 0.039 seconds with 23 queries.
Powered by SMF 1.1.18 | SMF © 2006, Simple Machines Design by 7dana.com