Menu

Show posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Show posts Menu

Messages - ArminF

#46
Ok hier ein Update:

Single Calls - udp 3478
Group Calls - udp 10000 bis 10100

Hab nun ein Alias (Network Grous) geschnürt.
Darin sind die DNS addressen und die AWS Server Ranges

Source: your LAN
Destination:
signal.org
cdn.signal.org
cdn-ca.signal.org
cdn2.signal.org
cdn2-staging.signal.org
contentproxy.signal.org
api.directory.signal.org
science.signal.org
status.signal.org
storage.signal.org
storage-staging.signal.org
support.signal.org
updates.signal.org
updates2.signal.org
uptime.signal.org
turn2.voip.signal.org
whispersystems.org
bithub.whispersystems.org
giphy-proxy-production.whispersystems.org
master.whispersystems.org
redphone-master.whispersystems.org
relay.whispersystems.org
support.whispersystems.org
textsecure-service.whispersystems.org
textsecure-service-ca.whispersystems.org
textsecure-service-staging.whispersystems.org
turn-eu-central-1.whispersystems.org
turn1.whispersystems.org
35.158.127.192/27
52.210.255.224/27
35.177.218.0/27
18.230.46.192/27


Ports: 443 TCP
443 UDP
3478 UDP
10000 bis 10100 UDP

jetzt gehen auch Group Calls
Werde weiter beobachten.

Danke an Alle für die Hilfe!!
#47
So jetzt hab ich mal den cousin gestresst mit Video Calls.

TCP 443
dazu UDP 3478 und 443.

Bisher laufen alles calls.
Das scheint es gewesen zu sein.

armin
#48
Danke,

ja 443 TCP hab ich für die Webports eh frei. Das würde Sinn machen die Regel auf UDP only zu reduzieren.
Und dann Stück für Stück und per Log die Range einzuschränken.

Recht hast Du! Ich mach den TCP raus.

Danke
armin
#49
Also das hat gefunktioniert.
Konnte den Call mit einem Freund testen.

Dennoch muss man wohl leider damit leben das diese "random" UDP Ports ausgewählt werden.
Zu mindest kann man die Destination etwas sicherer gestalten.

Danke
armin
#50
German - Deutsch / Re: Signal Messenger - Firewall Rule
January 13, 2021, 08:54:55 AM
JeGr,

herzlichen Dank für den Denkanstoss.

Ich hab nun mal folgende Subdomains gescannt mit https://www.nmmapper.com/sys/tools/subdomainfinder/
Und eine Alias List mit folgenden Server angelegt:

signal.org
cdn.signal.org
cdn-ca.signal.org
cdn2.signal.org
cdn2-staging.signal.org
contentproxy.signal.org
api.directory.signal.org
science.signal.org
status.signal.org
storage.signal.org
storage-staging.signal.org
support.signal.org
updates.signal.org
updates2.signal.org
uptime.signal.org
turn2.voip.signal.org
whispersystems.org
bithub.whispersystems.org
giphy-proxy-production.whispersystems.org
master.whispersystems.org
redphone-master.whispersystems.org
relay.whispersystems.org
support.whispersystems.org
textsecure-service.whispersystems.org
textsecure-service-ca.whispersystems.org
textsecure-service-staging.whispersystems.org
turn-eu-central-1.whispersystems.org
turn1.whispersystems.org

Nun die Regeln
- Source: LAN Net
- Protocol: TCP/UDP
- Destination: Alias (hosts) Signal Server
- Ports: Alias (Ports) 1024:65535

Mal sehen ob ich das einigermassen unter Kontrolle bekomme.

Danke!
gruss armin
#51
Hallo Zusammen,

laut Signal Messenger sollte man folgendes bewerkstelligen:
Allow *.whispersystems.org, *.signal.org, TCP port 443, and UDP traffic.  Signal uses a non-standard TCP port to catch filtering issues at the signaling step and also utilizes a random UDP port. All UDP ports will need to be opened.

Also Destination *.whispersystems.org, *.signal.org auf Port TCP 443 und UDP "All"
Bei den Ports hab ich keine Denkschwierigkeiten aber bei den Domains.

Würde es hier reichen einen Alias in den Firewall Settings anzulegen welcher auf whispersstems.org und signal.org hört? DIe * Domains gehen leider nicht?

Danke
armin
#52
Case closed...

Last DB and App Update fixed all of the issues.

@Sy -> thank you very much for your support!
#53
With latest update DB it does look much better.
No trouble yesterday. Lets see next days.

Thank you very much for your effort and support!


  • Updated to latest DB
    Removed Auto Whitelist entries
    Activated blocking on Apps again
    Restarted the Engine

Thanks
armin
#54
Works without Nord VPN now.


  • Updated to latest DB
    Removed Entry from Auto Whitelist
    Blocked Nord VPN again
    Restarted Engine

Thanks!!
#55
Hi Sy,

thanks. Ok updated to 1.6.20201209014859. Will restart the engine, remove my White List and report back.

thank you!
armin
#56
My google search gets blocked and tagged as Nord VPN.

Solution was to enable Nord VPN on the Apps tab or set google.com to the Auto Whitelist.

Any explanation on this? Very curious...

thanks
armin
#57
Updated to latest DB.

Removed all allowance for Youtube and Google ADS and set them back to blocking.

I do keep fingers crossed :)
Will report...
#58
Ok, i had to give up.

Had to enable google ADS and youtube ADS to get all the google services running proper.

Drive does not load content. Google Meet is not loading the meeting. Mail does not load background... etc.
Without these two options enabled in the App List the google services do fail on my network.

Reports show all actions as Youtube ADS or Google ADS blocked.
#59
Hi Sy,

so today a normal day like all the other working days.

For me it looks like the reload of the service engine did help to bring back to normal.
Most probably i have to to this after each change or update to get a clean state.

Auto Whitelist is reduced to
1   google.com      
2   lbryplayer.xyz         
3   youtu.be

And my wife is still happy :)

I will monitor further.
thanks for your help and support Sy!
armin
#60
Hi Sy,

excellent Link. Thank you.
Just added the dn.lbryplayer.xyz as content services.

thanks!
armin