Router behind Uverse Gateway can't block IP

af22

Gawd
Joined
Jun 21, 2010
Messages
610
Hello,

I have been running a m0n0wall router behind my uverse residential gateway fine for a while now. The m0n0wall router runs in DMZ+ mode, with my public ip address assigned to it.

I'm having trouble getting one feature to work properly. I can't seem to block external IP addresses with m0n0wall (blocking ports is no problem). m0n0wall seems to be only able to block the ip addresses from the uverse residential gateway.

Example:

Uverse Residential Gateway: 172:16:0:1
IP Range: 172.16.1.33 – 172.16.1.250

M0n0wall Gateway: 192.168.1.1
IP Range: 192.168.1.100-192.168.1.250

I have verified, m0n0wall can successfully block ip's from the uverse ip range of 172.16.1.33 – 172.16.1.250. But it can not block any public ips. My theory is since it's a NAT behind a NAT, m0n0wall can't see the public ip address.

I can do some simple tests by using my AT&T LTE connection connecting to a server I open to the internet. Then I can use my laptop to get a DHCP IP from the uverse gateway, while leaving my desktop behind m0n0wall.

Any advice would be appreciated.
 
Okay, i'm an idiot, i got this working.

I needed a rule to block both destination to LAN and WAN address from within m0n0wall.
 
Back
Top