Can I make an exception to allow ICMP?
Posted: Sat Jun 30, 2012 12:24 pm
Hello, here's my situation. Hopefully someone can point me in the right direction:
-On my router, I set static DHCP addresses for my children's phones and laptops. These addresses are NOT in the DHCP range.
-I've enabled "Block MAC addresses assigned a static IP that connect from a different IP".
So now, in theory, my kids can only connect to the network in the "Kids Block" of IP addresses.
Next, I setup a series of restriction rules:
-Allow my wife and I full access to everything
-Allow all addresses in the DHCP range full access to everything
-Allow access to specific websites only by domain for the "Kids Block" of addresses.
This all works fine and I'm really happy with it, but I've run into one problem: poptropica.com.
poptropica is a flash based adventure game for kids. It allows you to create a custom character and choose clothes and hats for them and all kinds of stuff. You can create a user id and password to remember your character. Here's the problem:
According to my amateur wireshark sleuthing, whenever you try to login with an id and password, the flash app tries to ping the poptropica website first. If the ping fails, then it doesn't even attempt to login and immediately throws up an error message about connectivity. If you just go to the site and create a new player, everything works just fine, so it would seem to be a login issue.
Is there any way to create a rule to allow ICMP traffic to a specific domain? Can you create a rule that allows ICMP for all clients?
I can allow ports, I can allow TCP or UDP, but I don't see a way to allow ICMP.
Any help would be greatly appreciated.
-On my router, I set static DHCP addresses for my children's phones and laptops. These addresses are NOT in the DHCP range.
-I've enabled "Block MAC addresses assigned a static IP that connect from a different IP".
So now, in theory, my kids can only connect to the network in the "Kids Block" of IP addresses.
Next, I setup a series of restriction rules:
-Allow my wife and I full access to everything
-Allow all addresses in the DHCP range full access to everything
-Allow access to specific websites only by domain for the "Kids Block" of addresses.
This all works fine and I'm really happy with it, but I've run into one problem: poptropica.com.
poptropica is a flash based adventure game for kids. It allows you to create a custom character and choose clothes and hats for them and all kinds of stuff. You can create a user id and password to remember your character. Here's the problem:
According to my amateur wireshark sleuthing, whenever you try to login with an id and password, the flash app tries to ping the poptropica website first. If the ping fails, then it doesn't even attempt to login and immediately throws up an error message about connectivity. If you just go to the site and create a new player, everything works just fine, so it would seem to be a login issue.
Is there any way to create a rule to allow ICMP traffic to a specific domain? Can you create a rule that allows ICMP for all clients?
I can allow ports, I can allow TCP or UDP, but I don't see a way to allow ICMP.
Any help would be greatly appreciated.