#1  
Old November 19th, 2011, 12:50 AM
DavidUK567 DavidUK567 is offline
Junior Member
NETGEAR Newbie
 
Join Date: Nov 2011
Location: UK
Posts: 11
DavidUK567 is on a distinguished road
Default DGN1000 Firewall schedule interferes with some websites

DGN1000 v1.1.00.41, several devices connect to the router. ISP is Plusnet.

Each device that connects to the router has a static IP assigned to it.
Each device has a firewall rule to either 'allow by schedule, otherwise block', or 'allow always'.
A schedule exists from 5am to 11pm.

2 PC's (both XP home, one wired, one wireless) that are 'allowed by schedule, otherwise block' cannot access certain websites. The browser tries to display the page but no content appears. Hotmail and Yahoo are consistent problems, while other sites can be browsed normally at the same time.

Deactivating the firewall rule and refreshing the browser page allows the problem website to be displayed normally.

Other devices that have 'allow always' rules do not suffer the same problem.

Anyone resolved this?

Thanks
David
Reply With Quote
  #2  
Old November 19th, 2011, 06:32 AM
jmizoguchi's Avatar
jmizoguchi jmizoguchi is offline
Senior Member
NETGEAR Fanatic
 
Join Date: Feb 2007
Location: Kentucky, USA
Posts: 88,642
jmizoguchi is on a distinguished road
Default Re: DGN1000 Firewall schedule interferes with some websites

Are you using block sites as well ?
__________________
VPN Case Study (www.vpncasestudy.com)
Our Second To None VPN Related Setup Case Study
"One Stop Solution To Your Netgear VPN Connectivity"
*Visit the site for Non-VPN related Doc & Links* [Windows & Mac user/support]

Most Other Useful Docs -"General Technical Documentation", "Router Reset", "Router Setup", "Print Server Tips", "Remote Admin"
"Wireless Tips"


Forum Policy

June Mizoguchi-i....@vpncasestudy.com
Reply With Quote
  #3  
Old November 19th, 2011, 08:28 AM
DavidUK567 DavidUK567 is offline
Junior Member
NETGEAR Newbie
 
Join Date: Nov 2011
Location: UK
Posts: 11
DavidUK567 is on a distinguished road
Default Re: DGN1000 Firewall schedule interferes with some websites

Quote:
Originally Posted by jmizoguchi View Post
Are you using block sites as well ?
No. I noticed with a previous netgear router that blocking sites did not work if a schedule rule was set. There are a lot of bugs in the advanced functions of these routers.
Reply With Quote
  #4  
Old November 19th, 2011, 09:06 AM
jmizoguchi's Avatar
jmizoguchi jmizoguchi is offline
Senior Member
NETGEAR Fanatic
 
Join Date: Feb 2007
Location: Kentucky, USA
Posts: 88,642
jmizoguchi is on a distinguished road
Default Re: DGN1000 Firewall schedule interferes with some websites

If schedule work and rest of domain site works then I would contact support sat my.netgear.com
__________________
VPN Case Study (www.vpncasestudy.com)
Our Second To None VPN Related Setup Case Study
"One Stop Solution To Your Netgear VPN Connectivity"
*Visit the site for Non-VPN related Doc & Links* [Windows & Mac user/support]

Most Other Useful Docs -"General Technical Documentation", "Router Reset", "Router Setup", "Print Server Tips", "Remote Admin"
"Wireless Tips"


Forum Policy

June Mizoguchi-i....@vpncasestudy.com
Reply With Quote
  #5  
Old November 20th, 2011, 02:36 AM
DavidUK567 DavidUK567 is offline
Junior Member
NETGEAR Newbie
 
Join Date: Nov 2011
Location: UK
Posts: 11
DavidUK567 is on a distinguished road
Default Re: DGN1000 Firewall schedule interferes with some websites

@jmizoguchi

You seem to know a lot about this stuff.

This from netgear about MTU. I'm wondering if the firewall rule 'adds' data to the packet, therefore taking it over the max MTU? It would explain the issue. I'll report back in a couple of days when I can try dropping the MTU right down and testing.
Reply With Quote
  #6  
Old November 20th, 2011, 02:39 AM
DavidUK567 DavidUK567 is offline
Junior Member
NETGEAR Newbie
 
Join Date: Nov 2011
Location: UK
Posts: 11
DavidUK567 is on a distinguished road
Default Re: DGN1000 Firewall schedule interferes with some websites

This from Netgear about MTU.

I wonder if the firewall rule modifies the data packet somehow, therefore taking it over the MTU?

I'll report back in a couple of days after I have tested.
Reply With Quote
  #7  
Old November 20th, 2011, 05:59 AM
jmizoguchi's Avatar
jmizoguchi jmizoguchi is offline
Senior Member
NETGEAR Fanatic
 
Join Date: Feb 2007
Location: Kentucky, USA
Posts: 88,642
jmizoguchi is on a distinguished road
Default Re: DGN1000 Firewall schedule interferes with some websites

DSL is common to be 1492

Usually range amount is 1400-1500
It is possible the MTU packet can cause some site issues. I had to deal with https site before

Test with lowering 10 at a time
__________________
VPN Case Study (www.vpncasestudy.com)
Our Second To None VPN Related Setup Case Study
"One Stop Solution To Your Netgear VPN Connectivity"
*Visit the site for Non-VPN related Doc & Links* [Windows & Mac user/support]

Most Other Useful Docs -"General Technical Documentation", "Router Reset", "Router Setup", "Print Server Tips", "Remote Admin"
"Wireless Tips"


Forum Policy

June Mizoguchi-i....@vpncasestudy.com
Reply With Quote
  #8  
Old November 26th, 2011, 03:46 AM
DavidUK567 DavidUK567 is offline
Junior Member
NETGEAR Newbie
 
Join Date: Nov 2011
Location: UK
Posts: 11
DavidUK567 is on a distinguished road
Default Re: DGN1000 Firewall schedule interferes with some websites

So finally a resolution. MTU seems to have been the issue, though I have not found an explanation why. Note, that this behaviour was found when I tested both netgear routers I have access to: DGN1000 and DG834Gv4, but not my old DG834Gv2.

To recap. If a schedule is in place to limit internet access to certain times (allow by schedule, otherwise block), PCs running WinXP or Ubuntu linux were unable to access certain websites at any time (Hotmail & Yahoo mail). Removing the schedule and refreshing the browser page with no other action being taken allowed the website to load.

Solution:
Set router MTU to 1458 as recommended by plusnet if there are issues.
Set MTU in linux (simple, but took a while to work out how to make the change permanent) to the same.
Set MTU in windows (the microsoft tool did not seem to work. Dr TCP did though) also to the same.

Subsequently the problem sites have loaded no problem with the schedule in place.
Reply With Quote
  #9  
Old November 26th, 2011, 05:27 AM
jmizoguchi's Avatar
jmizoguchi jmizoguchi is offline
Senior Member
NETGEAR Fanatic
 
Join Date: Feb 2007
Location: Kentucky, USA
Posts: 88,642
jmizoguchi is on a distinguished road
Default Re: DGN1000 Firewall schedule interferes with some websites

This is something you should contact support for bug at my.netgear.com
__________________
VPN Case Study (www.vpncasestudy.com)
Our Second To None VPN Related Setup Case Study
"One Stop Solution To Your Netgear VPN Connectivity"
*Visit the site for Non-VPN related Doc & Links* [Windows & Mac user/support]

Most Other Useful Docs -"General Technical Documentation", "Router Reset", "Router Setup", "Print Server Tips", "Remote Admin"
"Wireless Tips"


Forum Policy

June Mizoguchi-i....@vpncasestudy.com
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off



All times are GMT -8. The time now is 08:21 PM.