WAN ∈ LOCAL vs home website

Discussions about the Application Boundaries Enforcer (ABE) module

WAN ∈ LOCAL vs home website

Postby wagle » Sat Jun 23, 2012 7:41 pm

Starting with the June 12 release, I think, ABE stops me from getting to the blog portions of my local web sites unless I turn off the "WAN ∈ LOCAL" flag on ABE.

My web site is at home. Their IP address is my home WAN address. I can get to the top level web site (http://www.somedomain.org) just fine, but when I try to go to http://www.somedomain.org/blog (a wordpress installation), ABE starts getting in the way.

Turning off "WAN ∈ LOCAL" makes it work, but this seems to be the wrong solution. I feel like I'm leaving something out, what do I need to explain to get to the right solution?

Thanks!
Mozilla/5.0 (Macintosh; Intel Mac OS X 10.7; rv:13.0) Gecko/20100101 Firefox/13.0.1
wagle
 
Posts: 2
Joined: Sat Jun 23, 2012 7:25 pm

Re: WAN ∈ LOCAL vs home website

Postby Giorgio Maone » Sat Jun 23, 2012 8:49 pm

Can I see the exact message(s) you get from ABE?
Does downgrading to a pre-Jun 12 version actually help?
Mozilla/5.0 (Windows NT 6.1; WOW64; rv:13.0) Gecko/20100101 Firefox/13.0.1
User avatar
Giorgio Maone
Site Admin
 
Posts: 6830
Joined: Wed Mar 18, 2009 11:22 pm
Location: Palermo - Italy

Re: WAN ∈ LOCAL vs home website

Postby wagle » Sun Jun 24, 2012 11:57 pm

Doesn't repeat right now when I turn WAN ∈ LOCAL back on. There was some trouble with my WAN address changing (dynamic DHCP).

ABE wasn't visibly complaining, is there a log?
Mozilla/5.0 (Macintosh; Intel Mac OS X 10.7; rv:13.0) Gecko/20100101 Firefox/13.0.1
wagle
 
Posts: 2
Joined: Sat Jun 23, 2012 7:25 pm

Re: WAN ∈ LOCAL vs home website

Postby Thrawn » Mon Jun 25, 2012 12:09 am

Log is in the error console, Ctrl+Shift+j.

Good to hear that it's working now :). It would be tricky to add an exception since the address is dynamic.
======
Thrawn
-----BEGIN GEEK CODE BLOCK-----
Version: 3.1
GCM/CS/IT/M/S d++(-) s+: C++$ ULS$>++++ P(+) L++ W++
K- w V? PS-(---) PE Y+ PGP->++ t@ X R tv b++>+++ DI+@
!D G>+++ e++>+++ h--- r+++ m?
-----END GEEK CODE BLOCK-----
Mozilla/5.0 (Android; Mobile; rv:15.0) Gecko/15.0 Firefox/15.0a1
User avatar
Thrawn
Senior Member
 
Posts: 951
Joined: Mon Jan 16, 2012 3:46 am
Location: Australia

Re: WAN ∈ LOCAL vs home website

Postby GµårÐïåñ » Tue Jun 26, 2012 1:13 am

Just a heads up to all out there who are using either DSL/Cable (anything that is dynamically assigned by the ISP), if you happen to be in the middle of something on your machine and it happens to catch the modem/router in a cycle (meaning its renewing the IP or its rebooting, happens all the time) then you will temporarily have packets that have (without getting into too technical of a packet structure discussion) mismatching header/frame/source/dest ip addressees as well as IP CEF or local DNS cache mismatch causing ABE to trigger as a local block. That is NORMAL. Specially on Windows machine where in the absence of a valid IP/WAN connection, it creates and assigns virtual addressing which is indeed YOUR OWN MACHINE, hence, LOCAL.

Normally easiest and QUICKEST fix, wait until the cycle is complete, close your browser and try again and all is well in the world. If not an option, can't see why, then just open the link you were working on in a new tab and that should do it. Or all else fails, force a DNS update inside the browser, toggle the option and that should force a clean up for any cached entries. This information has come from lots of personal and observational experience. Hope it helps.
~.:[ Lï£ê ï§ å Lêmðñ åñÐ Ì Wåñ† M¥ Mðñê¥ ßå¢k ]:.~
[ Major's Blog ] .:. [ Security Pack ] .:. [ Productivity ]
Mozilla/5.0 (Windows NT 6.1; rv:13.0) Gecko/20100101 Firefox/13.0.1
User avatar
GµårÐïåñ
Lieutenant Colonel
 
Posts: 2820
Joined: Fri Mar 20, 2009 5:19 am
Location: PST - USA


Return to ABE

Who is online

Users browsing this forum: No registered users and 3 guests