Default Gateway

40 views
Skip to first unread message

Suporte

unread,
Feb 7, 2022, 10:30:15 AM2/7/22
to NxFilter - Brazlian Forum
Hello Good Afternoon, NxFilter has a place to configure the default gateway we have many subnets and I notice that NxFilter does not respond to queries from other subnets

Jahastech

unread,
Feb 7, 2022, 5:50:50 PM2/7/22
to NxFilter - Brazlian Forum
Are you sure that they can access NxFilter from the subnets? Enable debugging and look into /nxfilter/log/nxfilter.log.

This is about how to enable debugging,

Suporte

unread,
Mar 28, 2022, 7:09:30 PM3/28/22
to NxFilter - Brazlian Forum
After many attempts I found out why the connections do not happen the connections are not conserving the destination address in the response which causes the packets to be discarded this is because it is a connectionless udp protocol, after configuring the ubuntu kernel as routing table or packet marking I was not successful nxfilter insists on responding in the default route, I would like to know if nxfilter can work this way?
I redid some tests with bind9 dns server and to my surprise it works it responds conserving the input interface on which the packet was received, responding on the same interface, conserving the destination address from which the packet originated

Jahastech

unread,
Mar 28, 2022, 7:16:50 PM3/28/22
to NxFilter - Brazlian Forum
I don't know what you are trying to do. If it's about filtering multiple subnets try NxRelay. That'd be easier.

Tutorial,

Some guy asked about filtering bultiple branch offices with AD integration,

Some Brazilian guy using NxFilter + NxRelay for that,

This is a lot easier than your routing table modification approach.

Suporte

unread,
Mar 28, 2022, 9:06:44 PM3/28/22
to NxFilter - Brazlian Forum
What I need that nxfilter responds to a request on the same destination interface that the packet does not originate, because we have VPN tunnels, this problem is occurring because Nxfilter is installed in PfSense with multiple vlan interfaces which is causing the problem of routing that always exists of udp connectionless protocol, but I identified that it is possible to change the Nxfilter listening IP addresses in /conf/cfg.properties after changing from 0.0.0.0 all interfaces to a single interface it starts to respond on the same interface where the packet originated providing the connections between the subnets thanks very much 

Jahastech

unread,
Mar 28, 2022, 9:21:59 PM3/28/22
to NxFilter - Brazlian Forum
Yeah, multiple subnets. Try NxRelay. Whatever you do, you will have problems if you try to use multiple network interfaces.

And I don't understand why you talk about gateway here. NxFilter is not a gateway. It's a DNS server. And I don't know what's with bind9 thing. Usually, you can't set multiple listen IPs for a UDP server. Some guy asked about that and at first we thought it's a Java thing but later we tested with otehr softwares and they made the same result. UDP is basically connectionless. It doesn't know where it comes from if you have multiple listening IPs.
Reply all
Reply to author
Forward
0 new messages