<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns:pingback="http://madskills.com/public/xml/rss/module/pingback/" xmlns:trackback="http://madskills.com/public/xml/rss/module/trackback/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:dc="http://purl.org/dc/elements/1.1/" version="2.0">
  <channel>
    <title>Ghazi Sarhan's Blog - Modems/Routers</title>
    <link>http://blog.delmonbay.com/</link>
    <description>Can't Get Enough</description>
    <language>en-us</language>
    <copyright>Ghazi Sarhan</copyright>
    <lastBuildDate>Tue, 25 Dec 2007 00:17:25 GMT</lastBuildDate>
    <generator>newtelligence dasBlog 2.0.7226.0</generator>
    <managingEditor>ghazi@delmonbay.com</managingEditor>
    <webMaster>ghazi@delmonbay.com</webMaster>
    <item>
      <trackback:ping>http://blog.delmonbay.com/Trackback.aspx?guid=e62922d3-0053-4217-a60a-78a64fa22fe5</trackback:ping>
      <pingback:server>http://blog.delmonbay.com/pingback.aspx</pingback:server>
      <pingback:target>http://blog.delmonbay.com/PermaLink,guid,e62922d3-0053-4217-a60a-78a64fa22fe5.aspx</pingback:target>
      <dc:creator>Ghazi Sarhan</dc:creator>
      <wfw:comment>http://blog.delmonbay.com/CommentView,guid,e62922d3-0053-4217-a60a-78a64fa22fe5.aspx</wfw:comment>
      <wfw:commentRss>http://blog.delmonbay.com/SyndicationService.asmx/GetEntryCommentsRss?guid=e62922d3-0053-4217-a60a-78a64fa22fe5</wfw:commentRss>
      <slash:comments>2</slash:comments>
      <body xmlns="http://www.w3.org/1999/xhtml">
        <p>
Some people disable the Speedtouch's firewall just to enable the icmp-echoreply, which
is not correct, here is how to enable the icmp-echoreply on Speedtouch.
</p>
        <p>
First login to the Speedtouch's CLI using telnet, the default ip of the speedtouch
is 10.0.0.138.
</p>
        <p>
          <img src="http://blog.delmonbay.com/content/binary/telnet.jpg" border="0" />
        </p>
        <p>
 
</p>
        <p>
By default the speedtouch comes without username and password, just press Enter
on the username prompt, or type your username and password.
</p>
        <p>
On the speedtouch command prompt, copy and past the following:
</p>
        <p>
          <font color="#0000ff">:firewall chain create chain=input<br />
:firewall chain create chain=sink<br />
:firewall chain create chain=source<br />
:firewall chain create chain=output</font>
        </p>
        <p>
 
</p>
        <p>
          <img src="http://blog.delmonbay.com/content/binary/createchain.jpg" border="0" />
        </p>
        <p>
 
</p>
        <p>
Then... the following:
</p>
        <p>
          <font color="#0000ff">:firewall assign hook=input chain=input<br />
:firewall assign hook=sink chain=sink<br />
:firewall assign hook=source chain=source<br />
:firewall assign hook=output chain=output</font>
        </p>
        <p>
 
</p>
        <p>
          <img src="http://blog.delmonbay.com/content/binary/assignchain.jpg" border="0" />
        </p>
        <p>
 
</p>
        <p>
Then... the following:
</p>
        <p>
          <font color="#0000ff">:firewall rule create chain=input index=0 dstintfgrp=wan prot=icmp
icmptype=echo-request action=accept<br />
:firewall rule create chain=sink index=0 dstintfgrp=wan prot=icmp icmptype=echo-request
action=accept<br />
:firewall rule create chain=source index=0 dstintfgrp=wan prot=icmp icmptype=echo-reply
action=accept<br />
:firewall rule create chain=output index=0 dstintfgrp=wan prot=icmp icmptype=echo-reply
action=accept</font>
        </p>
        <p>
Finally:
</p>
        <p>
          <font color="#0000ff">Saveall</font>
        </p>
        <p>
 
</p>
        <p>
          <img src="http://blog.delmonbay.com/content/binary/createrule.jpg" border="0" />
        </p>
        <p>
 
</p>
        <p>
Now ping your wan ip from <a href="http://network-tools.com/">http://network-tools.com/</a></p>
        <p>
 
</p>
        <p>
If you want to know more about speedtouch firewall, check these sites:
</p>
        <p>
          <a href="http://www.speedtouch.nl/docs/AppNotes/AppNote_Firewalling.pdf">http://www.speedtouch.nl/docs/AppNotes/AppNote_Firewalling.pdf</a>
        </p>
        <p>
          <a href="http://www.fredshack.com/docs/alcatel.html">http://www.fredshack.com/docs/alcatel.html</a>
        </p>
        <img width="0" height="0" src="http://blog.delmonbay.com/aggbug.ashx?id=e62922d3-0053-4217-a60a-78a64fa22fe5" />
      </body>
      <title>Enable Ping Reply (ICMP-EchoReply) for Speedtouch 510/530</title>
      <guid isPermaLink="false">http://blog.delmonbay.com/PermaLink,guid,e62922d3-0053-4217-a60a-78a64fa22fe5.aspx</guid>
      <link>http://blog.delmonbay.com/2007/12/25/EnablePingReplyICMPEchoReplyForSpeedtouch510530.aspx</link>
      <pubDate>Tue, 25 Dec 2007 00:17:25 GMT</pubDate>
      <description>&lt;p&gt;
Some people disable the Speedtouch's firewall just to enable the icmp-echoreply, which
is not correct, here is how to enable the icmp-echoreply on Speedtouch.
&lt;/p&gt;
&lt;p&gt;
First login to the Speedtouch's CLI using telnet, the default ip of the speedtouch
is 10.0.0.138.
&lt;/p&gt;
&lt;p&gt;
&lt;img src="http://blog.delmonbay.com/content/binary/telnet.jpg" border=0&gt;
&lt;/p&gt;
&lt;p&gt;
&amp;nbsp;
&lt;/p&gt;
&lt;p&gt;
By default the speedtouch comes without username and password,&amp;nbsp;just press&amp;nbsp;Enter
on the username prompt, or type your username and password.
&lt;/p&gt;
&lt;p&gt;
On the speedtouch command prompt, copy and past the following:
&lt;/p&gt;
&lt;p&gt;
&lt;font color=#0000ff&gt;:firewall chain create chain=input&lt;br&gt;
:firewall chain create chain=sink&lt;br&gt;
:firewall chain create chain=source&lt;br&gt;
:firewall chain create chain=output&lt;/font&gt;
&lt;/p&gt;
&lt;p&gt;
&amp;nbsp;
&lt;/p&gt;
&lt;p&gt;
&lt;img src="http://blog.delmonbay.com/content/binary/createchain.jpg" border=0&gt;
&lt;/p&gt;
&lt;p&gt;
&amp;nbsp;
&lt;/p&gt;
&lt;p&gt;
Then... the following:
&lt;/p&gt;
&lt;p&gt;
&lt;font color=#0000ff&gt;:firewall assign hook=input chain=input&lt;br&gt;
:firewall assign hook=sink chain=sink&lt;br&gt;
:firewall assign hook=source chain=source&lt;br&gt;
:firewall assign hook=output chain=output&lt;/font&gt;
&lt;/p&gt;
&lt;p&gt;
&amp;nbsp;
&lt;/p&gt;
&lt;p&gt;
&lt;img src="http://blog.delmonbay.com/content/binary/assignchain.jpg" border=0&gt;
&lt;/p&gt;
&lt;p&gt;
&amp;nbsp;
&lt;/p&gt;
&lt;p&gt;
Then... the following:
&lt;/p&gt;
&lt;p&gt;
&lt;font color=#0000ff&gt;:firewall rule create chain=input index=0 dstintfgrp=wan prot=icmp
icmptype=echo-request action=accept&lt;br&gt;
:firewall rule create chain=sink index=0 dstintfgrp=wan prot=icmp icmptype=echo-request
action=accept&lt;br&gt;
:firewall rule create chain=source index=0 dstintfgrp=wan prot=icmp icmptype=echo-reply
action=accept&lt;br&gt;
:firewall rule create chain=output index=0 dstintfgrp=wan prot=icmp icmptype=echo-reply
action=accept&lt;/font&gt;
&lt;/p&gt;
&lt;p&gt;
Finally:
&lt;/p&gt;
&lt;p&gt;
&lt;font color=#0000ff&gt;Saveall&lt;/font&gt;
&lt;/p&gt;
&lt;p&gt;
&amp;nbsp;
&lt;/p&gt;
&lt;p&gt;
&lt;img src="http://blog.delmonbay.com/content/binary/createrule.jpg" border=0&gt;
&lt;/p&gt;
&lt;p&gt;
&amp;nbsp;
&lt;/p&gt;
&lt;p&gt;
Now ping your wan ip from &lt;a href="http://network-tools.com/"&gt;http://network-tools.com/&lt;/a&gt;
&lt;/p&gt;
&lt;p&gt;
&amp;nbsp;
&lt;/p&gt;
&lt;p&gt;
If you want to know more about speedtouch firewall, check these sites:
&lt;/p&gt;
&lt;p&gt;
&lt;a href="http://www.speedtouch.nl/docs/AppNotes/AppNote_Firewalling.pdf"&gt;http://www.speedtouch.nl/docs/AppNotes/AppNote_Firewalling.pdf&lt;/a&gt;
&lt;/p&gt;
&lt;p&gt;
&lt;a href="http://www.fredshack.com/docs/alcatel.html"&gt;http://www.fredshack.com/docs/alcatel.html&lt;/a&gt;
&lt;/p&gt;
&lt;img width="0" height="0" src="http://blog.delmonbay.com/aggbug.ashx?id=e62922d3-0053-4217-a60a-78a64fa22fe5" /&gt;</description>
      <comments>http://blog.delmonbay.com/CommentView,guid,e62922d3-0053-4217-a60a-78a64fa22fe5.aspx</comments>
      <category>Modems/Routers</category>
    </item>
    <item>
      <trackback:ping>http://blog.delmonbay.com/Trackback.aspx?guid=d2253683-8572-403c-af3e-f08337020acb</trackback:ping>
      <pingback:server>http://blog.delmonbay.com/pingback.aspx</pingback:server>
      <pingback:target>http://blog.delmonbay.com/PermaLink,guid,d2253683-8572-403c-af3e-f08337020acb.aspx</pingback:target>
      <dc:creator>Ghazi Sarhan</dc:creator>
      <wfw:comment>http://blog.delmonbay.com/CommentView,guid,d2253683-8572-403c-af3e-f08337020acb.aspx</wfw:comment>
      <wfw:commentRss>http://blog.delmonbay.com/SyndicationService.asmx/GetEntryCommentsRss?guid=d2253683-8572-403c-af3e-f08337020acb</wfw:commentRss>
      <body xmlns="http://www.w3.org/1999/xhtml">
        <p>
From the Speedtouch CLI, write:
</p>
        <p>
nat create protocol=tcp inside_addr=<font color="#0000ff">’address of the server PC’</font> inside_port=1723
outside_addr=0 outside_port=1723 foreign_addr=0
</p>
        <p>
nat create protocol=gre inside_addr=<font color="#0000ff">’address of the server PC’</font> outside_addr=0
foreign_addr=0
</p>
        <p>
 
</p>
        <p>
Note that it is required for the server to have a static ip on the
network.
</p>
        <img width="0" height="0" src="http://blog.delmonbay.com/aggbug.ashx?id=d2253683-8572-403c-af3e-f08337020acb" />
      </body>
      <title>Run a VPN server behind Speedtouch 510/530</title>
      <guid isPermaLink="false">http://blog.delmonbay.com/PermaLink,guid,d2253683-8572-403c-af3e-f08337020acb.aspx</guid>
      <link>http://blog.delmonbay.com/2007/12/19/RunAVPNServerBehindSpeedtouch510530.aspx</link>
      <pubDate>Wed, 19 Dec 2007 06:34:29 GMT</pubDate>
      <description>&lt;p&gt;
From the Speedtouch CLI, write:
&lt;/p&gt;
&lt;p&gt;
nat create protocol=tcp inside_addr=&lt;font color=#0000ff&gt;’address of the server PC’&lt;/font&gt; inside_port=1723
outside_addr=0 outside_port=1723 foreign_addr=0
&lt;/p&gt;
&lt;p&gt;
nat create protocol=gre inside_addr=&lt;font color=#0000ff&gt;’address of the server PC’&lt;/font&gt; outside_addr=0
foreign_addr=0
&lt;/p&gt;
&lt;p&gt;
&amp;nbsp;
&lt;/p&gt;
&lt;p&gt;
Note&amp;nbsp;that it is required&amp;nbsp;for the server&amp;nbsp;to have a static ip on the
network.
&lt;/p&gt;
&gt;&lt;img width="0" height="0" src="http://blog.delmonbay.com/aggbug.ashx?id=d2253683-8572-403c-af3e-f08337020acb" /&gt;</description>
      <comments>http://blog.delmonbay.com/CommentView,guid,d2253683-8572-403c-af3e-f08337020acb.aspx</comments>
      <category>Modems/Routers</category>
    </item>
  </channel>
</rss>