Recommended Posts

I recently replaced a Linksys E900 router with a m0n0wall router distribution, and on my local LAN or external WAN I can not open custom ports. I need to open the following for active directory/dns/etc.. to authorize, sync, and update.

RPC endpoint mapper: 135/tcp, 135/udp
Network basic input/output system (NetBIOS) name service: 137/tcp, 137/udp
NetBIOS datagram service: 138/udp
NetBIOS session service: 139/tcp
RPC dynamic assignment: Win 2k/2003:1024-65535/tcp
Win 2008+:49152-65535/tcp
Server message block (SMB) over IP (Microsoft-DS): 445/tcp, 445/udp
Lightweight Directory Access Protocol (LDAP): 389/tcp
LDAP ping: 389/udp
LDAP over SSL: 636/tcp
Global catalog LDAP: 3268/tcp
Global catalog LDAP over SSL: 3269/tcp
Kerberos: 88/tcp, 88/udp
Domain Name Service (DNS): 53/tcp1, 53/udp

I have a default LAN rule of:

Proto: * / Source: Lan Net / Port: * / Destination: * / Description: Default LAN -> any

So ANY traffic should be able to flow freely, yet I am getting error messages such as:

The DNS server could not open socket for address 192.168.1.1. 
Verify that this is a valid IP address for the server computer. If it is NOT valid use the Interfaces dialog under Server Properties in the DNS Manager to remove it from the list of IP interfaces. Then stop and restart the DNS server. (If this was the only IP interface on this machine and the DNS server may not have started as a result of this error. In that case remove the DNS\Parameters\ ListenAddress value in the services section of the registry and restart.) 
 
If this is a valid IP address for this machine, make sure that no other application (e.g. another DNS server) is running that would attempt to use the DNS port. 
 
For more information, see "DNS server log reference" in the online Help.
 
The DNS server could not bind a Transmission Control Protocol (TCP) socket to address 192.168.1.1. The event data is the error code. An IP address of 0.0.0.0 can indicate a valid "any address" configuration in which all configured IP addresses on the computer are available for use.
Restart the DNS server or reboot the computer.

 

I've researched on m0n0walls forums and have had no luck, is this a bug with the distro?

 

 

 

Link to comment
https://www.neowin.net/forum/topic/1196185-cant-open-m0n0wall-ports-bug/
Share on other sites

I'm not sure what the NAT would look like to only allow these local services to talk amongst the LAN.

 

Edit: I set up a rule for RDP as a test

 

IF: WAN PROTO: TCP EXT PORT RANGE: 3389-3389 NAT IP: 192.168.1.1 (server) INT PORT: 3389 DESCRIPTION: RDP

 

which works...

 

So to get LDAP to authorize it should be

 

IF: WAN PROTO: TCP EXT PORT RANGE:389-389 NAT IP: 192.168.1.1 (server) INT PORT: 389 DESCRIPTION: LDAP

 

But I don't get how to do a UNIQUE range, such as RPC using something like 1024-65534, since I can only map it to one local port as opposed to a range.

Do you have more than 1 lan segment? Your gateway/router has NOTHING to do with traffic between lan machines on the same network.

So unless your routing traffic between say 192.168.1.0/24 and 192.168.2.0/24 through m0n0wall. It does not care nor even see traffic between say 192.168.1.14 and 192.168.1.52

These devices would only talk to m0n0wall to go to something off 192.168.1.0/24, like the internet. You would not be opening up most of the ports you listed inbound from the internet - nor would you believe would you even want that traffic going to the internet. Other than your dns listing port 53

Where are you seeing this error?

"The DNS server could not open socket for address 192.168.1.1"

And what is the IP address of your m0n0wall lan interface.. I believe it would default to something 192.168

But generally specking those ports would have NOTHING to do with your m0n0wall setup for your local lan. And seem unlikely you would want those forwarded from the internet, etc.

Let me see if I understand you correctly:

 

(1) These errors are on the m0n0wall setup.

(2) You setup an outbound rule to allow passing of ANY traffic out.

(3) You are seeing socket errors when M0n0wall tries to bind to the DNS port on your LAN interface.

 

The binding to ports and outbound rules issue appear to be unrelated to me. It appears that m0n0wall's DNS server service is failing to bind to the DNS port (53) for some reason. I assume you are saying that all of the services you listed also fail to bind to ports in the same manner. Out of curiosity is m0n0wall having issues binding to ports above 1024? If not, this would probably indicate an issue with root vs non-root binding. Also, is your m0n0wall LAN interface actually configured to use address 192.168.1.1? If not, it would fail to bind.

Do you have more than 1 lan segment? Your gateway/router has NOTHING to do with traffic between lan machines on the same network.

So unless your routing traffic between say 192.168.1.0/24 and 192.168.2.0/24 through m0n0wall. It does not care nor even see traffic between say 192.168.1.14 and 192.168.1.52

These devices would only talk to m0n0wall to go to something off 192.168.1.0/24, like the internet. You would not be opening up most of the ports you listed inbound from the internet - nor would you believe would you even want that traffic going to the internet. Other than your dns listing port 53

Where are you seeing this error?

"The DNS server could not open socket for address 192.168.1.1"

And what is the IP address of your m0n0wall lan interface.. I believe it would default to something 192.168

But generally specking those ports would have NOTHING to do with your m0n0wall setup for your local lan. And seem unlikely you would want those forwarded from the internet, etc.

 

1) no, it is just one lan segment (192.168.1.x)

2) I am seeing this error in my DNS event viewer

3) The m0n0wall is 192.168.1.2 (firewall.eatvac.local) and the server is is 192.168.1.1 (zeus.eatvac.local)

 

Let me see if I understand you correctly:

 

(1) These errors are on the m0n0wall setup.

(2) You setup an outbound rule to allow passing of ANY traffic out.

(3) You are seeing socket errors when M0n0wall tries to bind to the DNS port on your LAN interface.

 

The binding to ports and outbound rules issue appear to be unrelated to me. It appears that m0n0wall's DNS server service is failing to bind to the DNS port (53) for some reason. I assume you are saying that all of the services you listed also fail to bind to ports in the same manner. Out of curiosity is m0n0wall having issues binding to ports above 1024? If not, this would probably indicate an issue with root vs non-root binding. Also, is your m0n0wall LAN interface actually configured to use address 192.168.1.1? If not, it would fail to bind.

 

1) the dns errors are from the server, I KNOW m0n0wall is the culprit, because if I put in a little SOHO router I do not have these issues

2) that is the default firewall rule that m0n0wall ships with

3) Yes, I believe that m0n0wall is preventing DNS from binding a port on the LAN interface. In m0n0wall my DNS is set to 192.168.1.1 (my DNS server - Standard 2008 R2)

 

Also, every so often I get internet disconnects (page can not be displayed) yet DCDIAG shows NO errors and passes everything.

So those errors are NOT from m0n0wall? They are from logs on a Windows machine running a DNS server? if so, it really has nothing to do with m0n0wall because m0n0wall cannot control what ports a completely separate machine is able to listening on. The best I can come up with is that possibly your Windows Server isn't keeping its 192.168.1.1 IP whenever m0n0wall is hooked up and as such can't listen to any ports on that address.

  • Like 1

So those errors are NOT from m0n0wall? They are from logs on a Windows machine running a DNS server? if so, it really has nothing to do with m0n0wall because m0n0wall cannot control what ports a completely separate machine is able to listening on. The best I can come up with is that possibly your Windows Server isn't keeping its 192.168.1.1 IP whenever m0n0wall is hooked up and as such can't listen to any ports on that address.

 

Which is totally a possiblity, except everything is hard coded... I'm not sure how it would "forget" - the issue does not occur though when I have a SOHO router on the network and remove m0n0wall from the equation.

Which is totally a possiblity, except everything is hard coded... I'm not sure how it would "forget" - the issue does not occur though when I have a SOHO router on the network and remove m0n0wall from the equation.

 

Is it possible that m0n0wall has control of the 192.168.1.1 address (e.g. to hand it out via dhcp or something) and a conflict is occurring?

 

EDIT: http://support.microsoft.com/kb/279678 could this be relevant?

  • Like 1

m0n0wall is static to 192.168.1.2 (firewall.eatvac.local) all DHCP services are disabled on m0n0wall.

 

Edit: If I follow the advice of the article and set the DNS server to only listen on 192.168.1.1 I lose all functionality of DNS.

If m0n0wall is actually on 192.168.1.2 and your dns server is on 192.168.1.1, and your seeing this error on your dns server.

WTF can that have to do with m0n0wall? There is NOTHING that m0n0wall could be doing that would effect anything your dns server on a different IP address does - nothing!!

So we are missing something here.. But I assure you if what your saying is correct m0n0wall is not part of the puzzle.

  • Like 1

If m0n0wall is actually on 192.168.1.2 and your dns server is on 192.168.1.1, and your seeing this error on your dns server.

WTF can that have to do with m0n0wall? There is NOTHING that m0n0wall could be doing that would effect anything your dns server on a different IP address does - nothing!!

So we are missing something here.. But I assure you if what your saying is correct m0n0wall is not part of the puzzle.

 

I'm sure you are correct, originally I thought it may have something to do, but I have since resolved SOME of those issues. The issue at hand is still that the DNS/AD server hasn't signaled a sync yet.. (EVENT 4013 - http://gslink.us/B8syka)

It was some weird DNS settings and I used kept running "best practice analyzer" and isolating down issues, event by event. I still actually have TWO issues, but I don't want to trouble others with this...

 

The best practice I DONT UNDERSTAND. I have my loopback as a secondary server.. in the adapter properties and in the DNS server.

 

 

 

 

DNS-4013.txt

DNS-Best-Practice-Error.txt

You normally point to 127.0.0.1 as secondary in case something wrong with the IP binding, or stack that prevents dns working on the IP assigned. It's really hard to break loopback ;)

does this server have more than 1 network interface - where exactly are you going to sync too. Do you have more than 1 AD dns server in your network. Do you have more than 1 DC? Where are all the roles located?

does this server have more than 1 network interface - where exactly are you going to sync too. Do you have more than 1 AD dns server in your network. Do you have more than 1 DC? Where are all the roles located?

 

It has 4, they are all disabled except for the one in use (since I do not have need for them). 1 AD DNS server only, and 1 DC only. Roles are all on the central/primary DC.

This topic is now closed to further replies.
  • Posts

    • Save 66% on a MagTag Ultra Slim Tracker Card for Apple or Android by Steven Parker Never Lose Anything Again with MagTag Today's highlighted deal comes via our Gear + Gadgets section of the Neowin Deals store where you can save 66% on this MagTag Ultra Slim Tracker Card - Works with Apple Find My App. Keep track of your world with MagTag, a sleek, ultra-slim, reliable tracker that’s built to help you safeguard your most important items. In the size of a credit card, just 1.5mm thick, you can slip MagTag easily into your wallet, backpack, passport pouch luggage…etc. Integrated seamlessly with Apple’s FindMy app, MagTag offers precise real-time global tracking, instant left-behind alerts, loud location beeping, and a long-lasting rechargeable battery. Whether you’re heading to work, on vacation, or simply running errands, MagTag ensures you never lose what matters most. No item left behind Precision Global Tracking: Works seamlessly with the Apple FindMy app, providing real-time tracking anywhere in the world, powered by the vast Apple network. Ultra Slim Design: At just 1.5mm thick and the size of a credit card, MagTag slips easily into your wallet, passport pouch, backpack, or luggage. Instant Alerts: Receive notifications the moment you leave behind your valuables, and locate them easily with a loud beeping sound. Versatile Attachment Options: With a built-in keyring hole, attach MagTag to keys, ID lanyards, kids’ bags, or name tags for easy access and protection. Long Battery Life & Wireless Charging: Lasts up to 5 months on a single charge and can be easily recharged with any Qi wireless charger. Durable & Waterproof: IP68 waterproof and dustproof built to withstand your adventures, perfect for vacations and everyday use, no matter where life takes you. Specs Color: Black Materials: ABS Dimensions: 0.05" x 3.35" x 2.13" (1.5mm x 85mm x 54mm) Ultra-slim Apple FindMy App Built-in keyring hole Battery life: up to 5 months Charging: Qi wireless IP68 rating (waterproof, dustproof) Manufacturer's 90-day warranty Good to know Ships to US Expected Delivery: Expected Delivery: Jun 23 - Jul 2 All sales final. This item is excluded from coupons. Here's the deal: This MagTag Ultra Slim Tracker Card (for Apple or Android) normally costs $59.99, but you can pick it up for just $19.99 for a limited time - that represents a saving of $19. For a full description, specs, and shipping info, click the link below. MagTag Ultra Slim Tracker Card now just $19.99 (was $59.99) Get the two-pack and save 70% Ships only to Contiguous US Support queries If you have queries or need support for any of the Neowin Deals, please use the contact form here. Neowin Deals are managed and sold by StackCommerce who represent Neowin on an affiliate basis. Why we post these deals We post these because we earn commission on each sale so as not to rely solely on advertising, which many of our readers block. It all helps toward paying staff reporters, servers and hosting costs. So for those that keep moaning and complaining, be thankful we're still online for you to even do that. Other ways to support Neowin Whitelist Neowin by not blocking our ads Create a free member account to see fewer ads Make a donation to support our day to day running costs Subscribe to Neowin - for $14 a year, or $28 a year for an ad-free experience Disclosure: Neowin benefits from revenue of each sale made through our branded deals site powered by StackCommerce.
    • I cannot believe this is a news post from Neowin. This should be embarassing, coming from a "senior editor". Is it your first day using Windows?! Maybe it's time to find a new Windows news site.
    • It's from having Core Isolation enabled in Windows security settings, which is a good thing!  It's letting you know it's not loading the Bonjour module as it's not signed in a way it would prefer. Bonjour was most likely installed along with iTunes. Feel free to disable that message using the checkbox.
    • I'm looking forward to starting over online. I have no reason to keep all the money, cars, rank after 13 years. Now if I can just move my character itself and nothing else. I would be fine with that. But I doubt they would do a setup that way.
  • Recent Achievements

    • Week One Done
      Huge Trailer earned a badge
      Week One Done
    • Week One Done
      Classifyskilleducation earned a badge
      Week One Done
    • One Month Later
      eurospharma62 earned a badge
      One Month Later
    • Week One Done
      With What earned a badge
      Week One Done
    • Week One Done
      Harris Gilbert earned a badge
      Week One Done
  • Popular Contributors

    1. 1
      +primortal
      588
    2. 2
      +Edouard
      169
    3. 3
      PsYcHoKiLLa
      74
    4. 4
      Michael Scrip
      66
    5. 5
      ATLien_0
      64
  • Tell a friend

    Love Neowin? Tell a friend!