1
General Discussion / Re: Sanity Check & Assistance Requested Enabling SMB Across Networks
« on: April 23, 2024, 11:51:52 pm »Hi,
do you access the SMB share with the asus router's LAN or WAN (aka lAN2) IP?
I can imagine the latter is not possible for security reasons. However, on LAN there might be an IP filter configured to allow local area IPs only. Furthermore, you don't allow access to LAN2 directly from LAN. You should run a packet capture and/or firewall live log inspection to check for possible blocks and/or no traffic at all.
Routes seem good, firewall rules for LAN 2 do not permit access to LAN when the respective rule is enabled. It's that intended? I didn't get that
Hey, just wanted to get back to you to let you know I was able to figure out the problem thanks to you! I was able to determine that I had to modify the `smb.conf` file on the router to expand the `hosts allow =` to include my other subnet. Once I did that everything worked! The only issue I have is with the default ASUS firmware it doesn't seem to run the script I added to `/jffs/scripts/smb.postconf` automatically. I rarely restart that router so hopefully it remains a non-issue to run it manually every now and again. If it does i'll look to install the custom Merlin firmware which I think will run the scripts automatically in that directory.
Anyway, thanks again!
I was wondering if you had any insights on my third question regarding hardening my WAN side? I'm reasonably confident in the security between the two local LAN networks, but I've not figured out how to have some level of confidence in my network security from the Internet. A link to some resources, or quick tips would be really helpful if you have any to hand? Is the default configuration of OPNsense out of the box OK?