dslreports logo
 
    All Forums Hot Topics Gallery
spc
Search similar:


uniqs
12441
rashire
join:2013-07-26
Warminster, PA

rashire

Member

ASUS RT-AC66U - Network Services Filter not working

Router: ASUS RT-AC66U
Firmware: 3.0.0.4.266

I've been trying to place a router level block for devices on my network so they can't access certain IP ranges and they don't seem to be working.

The why I found this article: »mitchribar.com/2013/02/h ··· s-guide/ when trying to figure out why youtube on my Viera TC-P55VT50 was stuttering so much it was unwatchable, and always has been. (Actually in general youtube had always sucked for me on Verizon Fios)

So I found some articles
»How-to: Reddit YouTube firewall rule with MI424wr
»forums.smallnetbuilder.c ··· ?t=10567

So I went into Firewall > Network Service Filter

I Enabled the Network Services Filter, and it is set to Black List

Destination IP 206.111.*.* - Protocol TCP ALL
Destination IP 173.194.*.* - Protocol TCP ALL

I left source IP and ports blank. ( I also expanded the 173.194.55.* to 173.194.*.* because it didn't seem to be working )

I hit apply and everything looked good to go.

Went to youtube and video still played, but looking at net information in firebug still shows connections with successful replies to 173.194.x.x on ports 80 and 443 ip/connection depending.

So I found this »superuser.com/questions/ ··· -ip-port to try and test if TCP traffic was actually being blocked. For which i get this result.


c:\Users\ED\Downloads\nc111nt>nc 173.194.29.46 80
echo
HTTP/1.0 400 Bad Request
Content-Type: text/html; charset=UTF-8
Content-Length: 925
Date: Sat, 27 Jul 2013 03:41:29 GMT
Server: GFE/2.0


A 400 response is still a reply from the server. So my rules aren't blocking tcp traffic to the ip ranges specified.

Is there something I did wrong, or another setting to make this work? Or should i just just unlazy and flash DD-WRT on this?

chamberc
Premium Member
join:2008-08-05
Addison, TX

chamberc

Premium Member

Use Merlins firmware.

PamelaTS
Digital Chick
join:2004-04-20
Dallas, TX
Asus RT-AC66
HTC 5G Hub

PamelaTS to rashire

Member

to rashire
said by rashire:

Router: ASUS RT-AC66U
Firmware: 3.0.0.4.266

I've been trying to place a router level block for devices on my network so they can't access certain IP ranges and they don't seem to be working.

The why I found this article: »mitchribar.com/2013/02/h ··· s-guide/ when trying to figure out why youtube on my Viera TC-P55VT50 was stuttering so much it was unwatchable, and always has been. (Actually in general youtube had always sucked for me on Verizon Fios)

So I found some articles
»How-to: Reddit YouTube firewall rule with MI424wr
»forums.smallnetbuilder.c ··· ?t=10567

So I went into Firewall > Network Service Filter

I Enabled the Network Services Filter, and it is set to Black List

Destination IP 206.111.*.* - Protocol TCP ALL
Destination IP 173.194.*.* - Protocol TCP ALL

I left source IP and ports blank. ( I also expanded the 173.194.55.* to 173.194.*.* because it didn't seem to be working )

I hit apply and everything looked good to go.

Went to youtube and video still played, but looking at net information in firebug still shows connections with successful replies to 173.194.x.x on ports 80 and 443 ip/connection depending.

So I found this »superuser.com/questions/ ··· -ip-port to try and test if TCP traffic was actually being blocked. For which i get this result.


c:\Users\ED\Downloads\nc111nt>nc 173.194.29.46 80
echo
HTTP/1.0 400 Bad Request
Content-Type: text/html; charset=UTF-8
Content-Length: 925
Date: Sat, 27 Jul 2013 03:41:29 GMT
Server: GFE/2.0


A 400 response is still a reply from the server. So my rules aren't blocking tcp traffic to the ip ranges specified.

Is there something I did wrong, or another setting to make this work? Or should i just just unlazy and flash DD-WRT on this?

You should be using a newer firmware first, 372 is current, works great.
rashire
join:2013-07-26
Warminster, PA

rashire

Member

said by PamelaTS:

You should be using a newer firmware first, 372 is current, works great.

Hmm, I'd used the routers functionality to look for new firmware and it said I was up to date. Also got impatient and did flash DD-WRT on it, which not only made the filtering actually work but got me sshd support.
said by chamberc:

Use Merlins firmware.

I'd looked into that before but I know just about nothing about it, what is the advantage to using this instead?