D-Link DIR-825 :: Get Both Allowed And Blocked Web Access Logging?
Nov 30, 2011
Is it possible to get both allowed and blocked web access logging? I'm using the 2.06NA firmware and no matter how I configure the router, I just can't get it to work, so either I'm missing something or the firmware has a defect, I hope its me, but I fear its a defect.
Does the Host file allow connections to your computer?Although I have placed some server names into the host file, Wallwatcher 5.0 is indicating that those servers have made connections. This didn't seem to be a problem before I took some online advice to add servers to my host file. I use iptables on a WNDR3700 router with DD-WRT firmware. In the iptable rules I've also blocked these servers. One example is cnbc7.net and a couple of U.S. Akamai servers.
Region : UnitedKingdom Model : TD-W8951ND Hardware Version : V1 Firmware Version : Latest ISP :
In trying to make sure it was NOT wide open to the internet (amongst many other problems of setting it up, which I ,may address later if I can actually connect to the thing ever again) I told it to only accept connections from a range of address inside the LAN. Now it wont accept anything except telnet from the LAN.Short of wiping out 6 hours of trial and error configuration and resetting it, are there any other options I can exercise via the telnet interface?
I'm trying to set up a website filter on my DIR-601. I created a policy for 2 MAC addresses, with a schedule from 10AM-6PM, selected "Block some websites", and disabled logging. Under website filter, I added some entries, and selected "DENY computers access to ONLY these sites". When the policy is enabled, and I try to access one of the blocked websites, it gets blocked correctly ("The URL access was denied by administrator.") However, for all other websites, I get "server unexpectedly dropped the connection" errors, eg "Safari can�t open the page [URL] because the server unexpectedly dropped the connection. This sometimes occurs when the server is busy. Wait for a few minutes, and then try again." or in Chrome "No data received. Unable to load the webpage because the server sent no data." This happens with ALL non-blocked websites. I'm using hardware version A1, firmware version 1.01NA.
I have yet another problem now with the DIR-825. I have a DAP-1522 that I connect my multimedia devices to like my TV, BD player, etc.
For added security, I use MAC filtering to only allow access to my devices that connect to my router. However, after several hours, the devices connected to my DAP-1522 can no longer connect and neither can I connect to them. The odd thing is that I can connect just fine to the 1522 itself. I NEVER had this issue with the DIR-655 so I figured it had to be the 825. After trying several things, I essentially narrowed it down to the MAC filtering.
If I turn MAC filtering off everything works fine all the time. If I turn it on, everything works fine for several hours, even up to a whole day, but then eventually my devices can no longer see or be seen.
Users behind a Cisco 1841 are not able to connect to a network using the Cisco Systems VPN Client. Transport is IP sec over UDP (NAT/PAT). Connection just times out.
Which ports should be allowed in the access list? Or do you have an link to a article for this?
I have a flashed Asus RT-N12B1 that was working but now has ceased working I am trying to get the info from the router using 192.168.1.1 ;but cannot get that working . I need to access the control panel in the router to change some parameters . To do that I have to access 192.168.1.1 .Safari does not allow me to do this .
I'm encountering what I think is an issue on logging system on FW ASA 5520 - Asa Version 8.4(2), ASDM version 6.4(5). When I disabled the logging inside a rule from ASDM, or from console with the "log disable" option inside ACL, If I check in ASDM logging real time window I continue to see all the entry related to disabled rules. This is a correct behaviour about ASA logging ? How I can "hide" the entry related to disabled rules (this is what I need for troubleshooting purposes) ?
I have recently setup Splunk to receive my syslog messages from my ASA 5510. In the past I used kiwi without observing this issue, but I needed more features than kiwi had available. Anyway, anytime I stop the splunk service my asa does not allow any outbound connections to be established.
My internet provider have blocked a website. I know there is a way to bypass the block and go to the website, without using websites such as Hide My ***! Free Proxy and Privacy Tools - Surf The Web Anonymously.
I have a brother who frequently blocks my internet access, and he does it while maintaining his own connection so he's not unplugging the router or anything. He also blocks it from his own computer, meaning he doesn't take out my wireless card or anything like that. I was wondering how to counter this and get my internet back whenever he blocks it, or prevent it.
how to get web logging working? I set up an Access Control policy for web logging only for one machine on my network. I also turned Syslog on and have Kiwi syslogd running on my desktop. However, it's not logging web traffic. how to get web logging working correctly?
UPnP renew entry 255.255.255.255 <-> 68.98.71.182:61041 <-> 192.168.0.197:61041 UDP timeout:-1 'Teredo' (this one repeated 13 times just in that 1 info slot)
Blocked outgoing ICMP packet (ICMP type 3) from 192.168.0.197 to 109.185.100.195
Blocked incoming TCP packet from 108.170.42.83:80 to 68.98.71.182:36792 as SYN:ACK received but there is no active connection
this goes on for a multiple of different ip's and i believe its due to the fact that the game i play is p2p
QoS is off spi is off udp and tcp endpoint independent firmware version 1.21 i am using wireless cable isp using motorola sb5101 i believe i port forwarded the ports used for the game but that didnt work so i put my computer into dmz. I've also noticed a lot more jitter then i used to have and my upload speed is down about 4mbps. Was thinking it might just be outdated firmware?
Yesterday I had the snapshots setup to be sent to my gmail account and now they've been blocked as spam. Is there anyway to get around this? The motion detection area is set to 90% so I see why I'm getting a bunch of snapshots. Is there a setting I can change on my gmail account or is the only option to reduce the percentage? I'd prefer to get all of the emails.
On my network I have a Netgear ReadNAS connected and I'm using an add-in (ReadyNAS Remote) that simplifies the log in to for both internet and LAN-users. However, I get a lot of the following entries in the log when that add-in is being used.
When an internet user log in via ReadyNAS Remote: "Blocked outgoing TCP packet from 192.168.0.xxx:3649 to xx.xxx.xxx.xxx:50125 with unexpected acknowledgement 3320366884 (expected 754541166 to 755655246)"
When a LAN-user log in via ReadyNAS Remote: "Blocked incoming TCP packet from 69.xxx.xxx.xx:80 to xx.xx.xx.xxx:50329 with unexpected sequence 3004123085 (expected 3004136875 to 3004393915)"
I am wondering if I can log all activity on my network. Right now I can log activity with MAC addresses, but if I add a device I have to keep adding MAC address. I also have to have several policies because I can only put about 7 MAC address in per policy.
I noticed the option to add 'other machines' and I am not sure how this works. I have tried it and can't get it to work.
I've been fighting with getting VPN connections working properly with my Dlink router. I set up virtual servers for PPTP and L2TP and could usually get the first attempt to work. Subsequent client connections would always fail.The logs display the following-Dropped GRE packet from 192.168.0.10 to 64.232.xxx.xxx as unable handle packet header. Blocked incoming GRE packet from 64.232.xxx.xxx to 76.105.xxx.xxx.What seemed to fix it was going to Firewall Settings and setting UDP Endpoint Filtering to Endpoint Independent and TCP Endpoint Filtering to Address Restricted.
I'm new to networking (at least at this level) and need some guidance. First, I have an Actiontec MI424WR (Rev. F) Coax Verizon Fios modem that I use as my home networking wireless router. From a LAN port on that I've connected a cable to the WAN port on my DIR-655 which acts as my gigabit office hard wire/wireless router. I need to keep the home network and the office network separate.All of my computers are Windows, either 7, Vista or XP.Connected to my Dir-655 on the office network are 2 wireless computers, a printer, an IOMEGA 1TB Home Personal Cloud NAS HDD, plus 2 desktop computers.The DIR-655 is set with a static IP address matching the range of the Actiontec. The DIR-655 is set for DHCP for the devices on the network (although 2 of the computers have static IP address).
When the DIR-655 had a Dynamic IP address set by the Actiontec, the IOMEGA NAS HDD kept losing connection with all the devices on the network. Only after I set the DIR-655 to static IP did that stop and everybody started to play nice. I'm not sure why that would make a difference, but it did.But regardless of whether it is set to dynamic or static, no computer on the network or program, even third party programs, can connect to ANY of the time servers out there... and I mean any of them. I've tried at least 20 or more of the standard and not so standard ones. The DIR-655's time is off, and it is set to get time automatically. None of my computers, or my IOMEGA NAS, can access time. The Actiontec, though, seems to be set correctly.Everything connects to the internet just fine. Web, email, auto product upgrades. Fine. So far it's just the time server thing which troubles.I done everything I know how to do to enable Port Forwarding through both routers for NTP > UDP 123 since that is the standard port for the Network Time Protocol, but I could have easily screwed that up.
Using a Samsung Galaxy S2, iPod Touch 3rd Gen, and Nook Color, they are all experiencing retry problems, even when 3 feet from the DIR-601. When I use them my log gets filled with messages like:Blocked incoming TCP Ack packet from 192.168.100.201:2926 to 209.85.145.113:80 with unexpected sequence On the devices I see the downloads/content taking a long time to appear and often I get a blank page or "Retry" messages. I purchased two DIR-601s and get the same problem with both. They are both running 1.02NA firmware. The WLAN is Time Warner cable modem. Prior to this I had a Linksys WRT-54 that gave great performance, though just at B/G speeds. I was hoping for a performance boost but right now the N speeds are slower than B with the retries.
There is a page in the DIR-825 that logs your computers IP and the other IPs it is connecting to. I was wondering if there was a way to disable that function on select devices? My handhelds and legitimate computers that should be on the internet are filling it with spam and it is hard to check for unauthorized users on the network. If that is not possible, then would I be able to completely disable the feature?
We are having a workgroup of 12 Pc connected using a switch (hub) having all Windows XP SP2 and some of them registered Kayspersky antivirus 2011. We have internet access using D-Link 2460T (DSL wireless ADSL router) connected to our LAN using a network wire and having DHCP enabled. Everything was working well for 4-5 years but recently a problem appeared.
Uninstalled McAfee. Installed Frontier Secure, which uses the Windows Firewall. Received Windows Security Alert message that my Belkin USB Storage Center (where the printer is listed) was being blocked, and would I like to allow access. I selected "Allow Access". Printer has not been connecting all week. No error messages - it tries to connect, and then just stops. Can't find issues with the router or the printer - only with the firewall. Everything looks the way I assume it should - the printer is listed in the Belkin storage center. The Belkin storage center is listed in the firewall. There is no tech support for the firewall. There is no tech support for the printer.
We have an ASA 5520 in HA. (version 8.X upgraded to 9.1 (1))We used Wizzard to configure VPN clientless and portal. Also, configured manually we have the same issue: We can access to the portal using IP address of Lan interface but not with outsides (2 ISP). The clientless VPN is enable on the public interface and no packets rejected in logs.We try to modify the Crypto map created by default to replace "any" to "any" by "any" to "our public IP" (We see that is recommended by Cisco) It works for 10 minutes.(strange..) but after 10 minutes the active member crashs.. only a reboot with previous configuration was good.We try to investigate but each time we modify Crypto maps, the firewall is going bad.
Region : UnitedStates Model : TL-WDR4300 Hardware Version : V1 Firmware Version : Latest ISP :
The UDP connections are being blocked when I use my VPN. I can connect for a while but soon after a while, the connection doesn't work. I can't even access the router page.
I am using firmware version 1.0.04 build 6.I am having a few issues viewing the log; the incoming, outgoing and security logs are completely blank, the DHCP log is the only one populated.Even though it's populated, the time stamp displays the date as Jan 1 1970, time appears fine if I use UDT (Time is set to Mountain), the Router Status correctly displays the current time for my location.I vaguely remember the other logs worked with a previous firmware 1.0.03? Don't recall if the Date Time stamp was working correctly.
In the ISE documentation is states that under a Guest_Activity report you must have guest access logging enabled on the NAD in the ISE network. My question is where do I enable guest access logging in the WLC that is our NAD?
I'm setting up WHS 2011 for the first time. When attempting to set up Remote Web Access, WHS continues to recoginze my E4200 model information and router IP address but delivers the message 'Remote Web Access to Your Server is Blocked'. Cisco and MS say the router is compatible with WHS and that it should set up through the wizard but no luck following many attempts, including manual set up of DHCP Reservation and Single Port Forwarding on ports 80/443 (not sure I did this correctly).
I've taken the router back to default settings with the exception of enabling Remote Management under the Remote Management Access section of the Administration menu tab; tried again with the same result. What settings to change to make this work?
I'm getting this error message on syslog server (Kiwi syslog)access-list logging rate-limited or missed XXXX packets i did the following commands but still I'm getting the error :logging buffered 16386 debugginglogging rate-limit all 5000no logging consoleno logging monitorip access-list logging interval 30000ip access-list log-update threshold 30000 i don't want to report to the console or monitor i want to report direct to syslog server, because I'm monitoring all the traffic (permit ip any any log) !