monowall woes

bob

2[H]4U
Joined
Feb 13, 2002
Messages
2,971
Box: 500Mhz K6 with a squealing fan, no hard drive, CD/Floppy monowall (till my CF-> IDE adapter arrives). SMC 10/100 PCI nic for the Wan (RL1), Realtec 82-something or other 10/100 (R0). 415 Megs of PC100 ram.
ISP : Comcast, 4mb cable.
Modem : Terayon TJ715

Heres the story : My main rig, the 2 year old box that some of you helped me choose parts back in late '04... Its been with comcast for about a month. No router, firewall or anything between me and the intarweb, and after coming home on my lunch-break seeing AVG having a panic-attack over virus infested DLLs, and seeing how my upload was maxed out, to some weird IPs in china... Ive decided its time to get a router, but Im not going to blow $100.00 on some Soho router which most likley sucks at life.

Ive wasted the past 3 hours of my afternoon ripping apart my laptop for its floppy drive, pulling out my PCs nic to find that monowall wouldnt work with it... Digging around in my closet for some generic SMC/Realtec NICs... It goes on. Its up, the monowall box responds to pings on the LAN side, I can ping its WAN ip. Had the web config up and ran the traffic shaper wizard in anticipation of some serious torrent hammering, all for this.

I cant ping anything past the WAN nic. My first guess was comcast uses mac filtering in one way or another, so I cloned the MAC Address from my Nforce onboard. That didnt do much. Cloned MAC or not, the WAN interface gets an Ip, subnet, gateway and DNS via dhcp from comcast.

Yes, I have read the monowall getting started guide. If I can set up Freesco to connect to a WISP, or can get a 286 Zenith with a 2400baud modem connected to a dial-up ISP... I figured I would know enough to get by with monowall.

And yes, I have called comcast. I told the tech that I had just plugged in my "Router" to the modem, and it can get an ip Via dhcp but cant ping anything. The response to that was "...ok", proceeded by a "ok lets power cycle your modem and router". I asked him if I need to clone the mac or do anything else, he said no.

I dont know where to go from here. I have some screenshots of my modem, so we can instantly rule that out of any conversation (see for yourself). The modems interface is about the most useless peice of crap ive ever come across.
Modem screenshot 1
Modem screenshot 2
Video of me poking around in monowall, DivX 5.2

Id apreciate any comments or help, id rather not leave a box running 24/7 behind no firewall that has VNC, FTP, VPN, HTTP, and a few other things like HL1, OpenTTD, Ta Spring, and Teamspeak running...
 
Comcast doesn't authenticate via MAC....but the modems memorize the MAC of the device previously connected to them.

Just power off your modem for 15 minutes or so...plug it into the RED NIC..monowall powered up already. Power up the modem. Once synched...do a release/renew on your mono.

I've gone some days where I've swapped up to 6 different devices. That's all it takes with Comcasts home accounts.
 
YeOldeStonecat said:
Comcast doesn't authenticate via MAC....but the modems memorize the MAC of the device previously connected to them.

Just power off your modem for 15 minutes or so...plug it into the RED NIC..monowall powered up already. Power up the modem. Once synched...do a release/renew on your mono.

I've gone some days where I've swapped up to 6 different devices. That's all it takes with Comcasts home accounts.

By RED NIC, do you mean RL1 (WAN)?
 
Does Comcast give you a public or private IP? If it's private, make sure your internal subnet uses a different range or you'll have routing problems. Just a guess off the top of my head.
 
Actually, I just watched the video. You are getting a gateway of 67.185.40.1 which is not on the same subnet as the IP of 67.185.43.251/29. Looks like a DHCP problem at Comcast. You address range for that IP is 67.185.43.248-67.185.43.254 with 67.185.43.255 as broadcast.

Oh, and I think you need a few more icons on the desktop... :)
 
no, its in the range. for the subnet mask 255.255.248.0 (aka /21), the network address 67.184.40.0. the first ip is 67.185.40.1, and last ip is 67.185.47.254.
 
bob said:
Ive decided its time to get a router, but Im not going to blow $100.00 on some Soho router which most likley sucks at life.

Ive wasted the past 3 hours of my afternoon ripping apart my laptop for its floppy drive, pulling out my PCs nic to find that monowall wouldnt work with it...

You should have just bought a router, but...

For the best performance from your m0n0wall box use Intel NIC's if you have them.
 
i can ping the ip, the host is up.

[jhorne@athena ~]$ ping 67.185.43.251
PING 67.185.43.251 (67.185.43.251): 56 data bytes
64 bytes from 67.185.43.251: icmp_seq=0 ttl=50 time=80.102 ms
64 bytes from 67.185.43.251: icmp_seq=1 ttl=50 time=79.928 ms

bob, how are things going? i use pfsense, which was forked from monowall. (we probably wont see him online for a while i guess). you can hit me up on aim or yahoo at LoudRedZ71 and i might be able to help you get it sorted out.
 
Met-Al said:
You should have just bought a router, but...

For the best performance from your m0n0wall box use Intel NIC's if you have them.
Im sticking with the dual port Compaq nic, it seems to peform quite a bit better than my onboard Nforce as far as cpu load goes. The intel NICs would just be another $20-30 to add to the bill. As far as just buying a router, I really havent seen any that have the features I need, for a reasonable price. If it came down to spending money for something new, id get on ebay and spend ~$80.00 on a mini-itx board, 5-10 for a right-angle PCI riser card, and stuff it into something, possibly inside my 1U switch. Yeah, you could say im not giving the newer routers a chance, but im not the type to spend money on a pre-made item, knowing I could figure out a DIY solution :eek:.

anyways... Im back up online with my ass hanging out (no router/firewall). So, Im sure theres all sorts of other things that could be done to my pc aside from pinging it. I unplugged the modem, and went and watched tv for awhile. Turned on the monowall box, plugged in the modem. DHCP assigned an IP, and I couldnt do much of anything. Im half-tempted to try freesco and see if anything happens.

and it seems Im not the only one with this issue : http://m0n0.ch/wall/list/showmsg.php?id=169/11

I may try FreeSCO later on to see if its just monowall. Ill also unplug the modem overnight and see if anything changes.
 
bob said:
Im sticking with the dual port Compaq nic, it seems to peform quite a bit better than my onboard Nforce as far as cpu load goes. The intel NICs would just be another $20-30 to add to the bill. As far as just buying a router, I really havent seen any that have the features I need, for a reasonable price. If it came down to spending money for something new, id get on ebay and spend ~$80.00 on a mini-itx board, 5-10 for a right-angle PCI riser card, and stuff it into something, possibly inside my 1U switch. Yeah, you could say im not giving the newer routers a chance, but im not the type to spend money on a pre-made item, knowing I could figure out a DIY solution :eek:.

I had a m0n0wall going on a IBM 1U server and it was awesome. I snaged the server for ~$80 off of eBay, it had a P3 500 on a SMP board with dual Intel NIC's. The only downside and the reason I finally stopped using it was the noise, heat, and the electricity it used. I am now using a DGL-4300 which is suiting my needs pretty good. If I had a basement to put my network stuff in, I would probably still be using my m0n0wall and my Cisco switch.

EDIT: Once you get it going, grab Monomon. Its a nice little utility that will let you see the bandwidth going in and out of your m0n0wall either in your systray or a window.
http://monomon.matf.de/
 
Alright, Sharaz Jek deserves a beer or two. Helped me out this morning, and the box is now up and running with PfSense.

Connecting to FTP servers seems to be a bit flakey, wont work at all under filezilla, some will work under IE... But for the most part, I think I just saved myself from blowing at least $100 on a router.
 
bob said:
Connecting to FTP servers seems to be a bit flakey, wont work at all under filezilla, some will work under IE... But for the most part, I think I just saved myself from blowing at least $100 on a router.
I believe pfSense has a FTP proxy. You could try disabling it.
 
correct. there are 2 places you can tweak ftp behavior. one is on the interfaces/wan page, and one is on the sytem/advanced page. tweak one then the other then both until you hopefully get the behavior youre looking for.
 
Sharaz Jek said:
correct. there are 2 places you can tweak ftp behavior. one is on the interfaces/wan page, and one is on the sytem/advanced page. tweak one then the other then both until you hopefully get the behavior youre looking for.

Ive got it all fixed, I had to open up a few more ports to allow filezilla to work in passive mode. Thanks to all that helped, its now working great.
 
Back
Top