
New Member
•
7 Messages
Disable FW on BGW320-500
Hello,
I'm trying to disable the FW on device BGW320-500. I already seitch off all the security features.



Even with all the security features disable there are some ICMP traffic being blocked.

Can anyone told how to fully disable the FW?
Thanks
JefferMC
ACE - Expert
•
32.3K Messages
1 year ago
The "Invalid IP packets" apparently were ill formed. There's no point in passing badly constructed packets. The others probably didn't pass because they are unsolicited traffic.
Have you configured your Gateway to tell it what to do with Unsolicited Traffic, given that those are IPv4 addresses and NAT is likely involved?
0
pcaminog
New Member
•
7 Messages
1 year ago
You are right, that is ICMP traffic egressing my WAN but the ingress was through a GRE tunnel. So the gateway is not able to keep the ICMP state.
How can tell the gateway what to do with this type of traffic??
I thought FW was what controlled that.
0
0
JefferMC
ACE - Expert
•
32.3K Messages
1 year ago
There are a variety of destination IPs on those ICMP packets? Are you sure those are associated with your PP2P tunnel?
Sorry, misread what you said. GRE packets won't say they're TCP packets. A TCP packet inside a GRE tunnel wouldn't show up as a TCP packet here, because it's encapsulated in the GRE traffic.
When running a single IPv4 address on your router with multiple devices behind it, you have NAT. When you have NAT, and an unsolicited packet arrives, the router needs specific instructions on what to do with it. The setup for IP Passthrough and Port Forwarding (under NAT/Gaming) can tell it what to do.
(edited)
0
pcaminog
New Member
•
7 Messages
1 year ago
The NAT thing is not applying to me, I do have a Public /29 block and the 104.X.X.X is assigned directly to the FW WAN interface, so the ATT GW is not doing any NAT, all traffic egress from my FW WAN already NATt'ed.
For me, the ATT router is the GW of my WAN interface. So I don't need Passthrough or something like that, what I want is that GW act as L3 router, not as a L4 gateway
Thanks
0
0
JefferMC
ACE - Expert
•
32.3K Messages
1 year ago
Ah. You could have mentioned such details. Given static IPs, you should be good to go.
0
0
pcaminog
New Member
•
7 Messages
1 year ago
I'm not, the ATT Router is still blocking that ICMP traffic.
Any idea how to solve it?
0
0
JefferMC
ACE - Expert
•
32.3K Messages
1 year ago
It's dropping packets it has determined are malformed. You're not going to change that behavior.
0
0
browndk26
ACE - Professor
•
5K Messages
1 year ago
@JefferMC In the first post the OP has everything under firewall off. Can the gateway actually pass traffic through the gateway with all those turned off?
0
0
JefferMC
ACE - Expert
•
32.3K Messages
1 year ago
Yep. Turning things "off" there typically means to not block traffic in that category, so "Off" means less filtering, more traffic.
0
0
browndk26
ACE - Professor
•
5K Messages
1 year ago
So in the OP’s setup the FW/router is controlling all traffic and the gateway is just a connection to the internet like a cable modem?
Could I turn off ip passthrough in my own setup and still connect to the internet with a wireless router connected to the gateway?
(edited)
0
0