*** Moderator copied text from Summary to Body section of the Forum post ***
Are there any known issues with the installation of blockknownencryption? I have tried applying to nodes only to find it appears to be blocking all web access regardless of page content. I would have anticipated receiving warnings that a page could not be viewed due to encrypted content rather than blocking everything.
Keith
Best for someone to create a bloodhound ticket to get this on the developers radar.
I believe if I had not had the check box checked to save config on the firmware upload it would have went back to the default IP and I could of accessed it from my Pi2 server....Lessoned learned..
firmware is 3.16.1.1 and it totally blocked all ip traffic through its wan port....???
The block known encryption package has been upgraded and is now installable in 3.17.1.0RC1 (and future versions). A 'refresh' in setup->administration->package_management, if connected to the internet, will make it selectable to install. Otherwise, manually download from:
http://downloads.aredn.org/releases/3/17/3.17.1.0RC1/ar71xx/generic/packages/arednpackages/
This package download is not built for (meaning is not compatible) in 3.16.x.x or prior versions.
Joe AE6XE
Is there still an approved package that dose this? Or is there a suggested method to enable this function?
blockknownencryption package in nightly build.
Also, a package will install these rules: http://downloads.arednmesh.org/snapshots/trunk/packages/mips_24kc/arednpackages/blockknownencryption_2.0.0-1_mips_24kc.ipk
Joe AE6XE
Joe AE6XE
I thinks I will be removing the ssh rules.
I don't run nighty on my tunnel server so I will place rules on a gateway and see how it works.
Im really looking to put together something more like a Firewall with the control like PFsence. The cheep hardware doesn't provide the bandwidth. I wish CISCO would let me evaluate some SDWAN equipment.
Wanted to mention that I tried getting the package by clicking the "Refresh" button in the Package Management section of the Admin page. It gave me a bunch of error messages, mostly consisting of lines where it was downloading something, followed by these 2 lines:
Signature check failed.
Remove wrong Signature file.
The list never seems to populate. I've tried it several times, on different devices, over the last 2-3 days.
Any idea if I'm doing something wrong, or is the system that provides the package list not working right?
(OR, if you are a risk taker, you can edit /etc/opkg.conf and remove the line: option check_signatures)