• This site uses cookies. By continuing to use this site, you are agreeing to our use of cookies. Learn more.
  • The forum software that supports hummy.tv has been upgraded to XenForo 2.0!

    This is a major upgrade which changes the look and feel of the forum somewhat but brings a host of improvements too. Please bear with us as we continue to tweak things and report any issues or suggestions in Site/Forum Issues.

Firewall ?

#1
Hi

Is there any firewall in the HDR-T2 ??

I'd like to block access to my box from a set of IP addresses.
So Block everything from 192.168.1.3-30

Thanks for your advice.
 
OP
OP
T
#3
Yes and no... Yes for external access, no for the office to home openvpn link..
I was hoping I can do some on the box !
 

Black Hole

May contain traces of nut
#4
The short answer is "no"... but there may be something that could be done through a custom package. If you can identify a Linux utility that achieves what you want, put it up for porting to the Humax.
 
#6
I asked about this before I started recommending Humaxes (I help out with local dissability issues) and was advised not to connect
them to local networks as they could present security hazards. (As could the random connection of TV's/bluray players etc)
These issues seem to be completely ignored.
I did ask online somewhere if there was firewall support (cant remember if I asked here or elsewhere)

My point is - I'm seconding the request for firewall - ideally everything blocked until an IP address AND port AND protocol is specifically allowed.
ARP, most UDP and other protocols should also be dissabled. Personally I'd like to see all IPV6 blocked permanently.

Anyway - Whatever the details it would be nice if someone could look into it.
 
#7
You can put devices that you want to limit access to behind their own router. This has the added benefit of working even if the device in question is a black box whose internals are not accessible.
 

xyz321

Well-Known Member
#8
The netfilter/iptables option doesn't look very straight forward. It would require a kernel change. I don't think anyone has yet managed to load a new fully working kernel onto the box.