-
-
Notifications
You must be signed in to change notification settings - Fork 487
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Firewall rules for Windows 10 hotspot #425
Comments
I think this system rules do enabled to allow this feature:
Correct answer with blocked hotspot ports in log. |
Same problem, I tried the suggest from @henrypp, also tried to allow 192.168.0.0/16 and local ports "1900;2869;53;67;68" for all apps and only for svchost.exe, but in the log I have next entries: OS version is Windows 10 Enterprise LTSC 10.0.17763.720, Simplewall version is 2.4.6.0 |
Same here, can't make it to allow Windows 10.1903 Hotspot (( |
I'm here to tell you that the problem is for real and exists for Windows 10 1909 and Simplewall 3.0.9. It tooke me several days to realize it's not a problem with intel wifi drivers and the new windows driver model (which disallows hosted networks / soft-ap from now on and you are forced to use microsoft windows mobile hotspot). The mobile hotspot is up and running, but clients can only connect via lan/smb and they don't get internet access, that's the actual problem. I tried all of the above, always checked blocks in the logs, made custom rules to allow them and even more, yet it is not possible to fix this by adding/removing any rules to the user filters, nor by checking/unchecking any of the available progam options. The only way to make the windows mobile hotspot work is to completely disable simplewalls filtering and the mobile hotspots internet will work immediately. will try to add more log information for this issue soon we need to figure this out, because something is wrong with the general filtering. |
@henrypp can you please take a look into this issue? there seems to be a problem which might be deeper than expected. I did some additional tests and I'll provide you some logs and screenshots. for that, I reinstall simplewall to start with a fresh installation and default settings. For testing, I will always enable the win10 mobile hotspot, connect with my android phone, let simplewall log all it is blocking, look at the blocks and adjust rules, disable the mobile hotspot, delete simplewall.log and repeat all over again until there is nothing left to do. For the beginning, I'll provide you screenshots of the overall simplewall settings: The system rules (I enabled everything): User rules: So let's start testing. The first thing that looks strange is that despite my LAN subnet rule which sould cover and allow everything in the The next strange thing is: simplewall blocks DHCP traffic despite the DHCP system rule which should allow exactly this DHCP traffic: For testing I created custom rules to handle each multicast DHCP traffic, so that simplewall no longer brings the block pop-up windows.
Now, when I disable and enable the Win10 Hotspot, Simplewall shows no blocking pop-ups anymore. I would assume that simplewall doesn't block anything that could prevent the mobile hotspot from working. But it still does. Connecting from my phone to the hotspot still show "no internet available". Let's take a look at the simplewall.log what still gets blocked: First of all we see here the Then we see again a lot of DHCP traffic that gets blocked. Why does it get blocked? This traffic is already allowed twice: For one time in the system rules with the DHCP rule (see screenshot above again) and for the second time with my user created rule I mentioned above. I think this is the reason why it is possible to have a connection with the mobile hotspot on the one hand but we don't get any internet on the other hand - because the DHCP and SSDP traffic still gets blocked. When I disable simplewall filtering, the android phone connected to the w10 mobile hotspot instantly gets internet access. I can't fix this issue by adding user rules to simplewall, because it blocks traffic despite having allow-rules. There must be something wrong on simplewalls side, with detecting loopback traffic with the virtual wifi/hotspot adapter. @henrypp I strongly recommend testing this for yourself as the problem seems to be anywhere where you have to dig deeper into the code. |
@henrypp a few things to add: have you tested simplewall against windows 10 1909? update about my quote from above:
I just realized that the reason for this is not a mistake by simplewall, it was the setting "Stealth mode" in the simplewall settings. So this is not a problem it was on purpose by this setting, sorry for that. anyway.. I disabled the windows defender firewall service for testing, also unchecked stealth mode for testing and yet simplewall seems to block the mobile hotspot from having an internet connection for the clients. |
even more information: Now I did the following: I reset the original windows defender firewall rules back to standard setting it to its original state. Then activate the windows defender firewall while simplewall filters are ALSO active. And suddenly the mobile hotspot works with internet connection for the mobile phone.
not exactly the solution we would prefer, though.... Update:
As soon as simplewall filtering is enabled and windows firewall dissabled, the hotspot internet access stops working. Despite it is not working and it is obviously blocking something, simplewall.log does not show up anything that gets blocked, it is empty after re-enabling the hotspot and letting a client connect. There is nothing to unblock and therefor nothing we could do. out of ideas at the moment, it's your turn @henrypp
|
Hi, I have the same problem as the Windows 10 hotspot not working with SimpleWall activated. |
Some resources: What is Hosted Network (hotspot uses this) Using Hosted network |
Anyway. |
Any progress? I have the same issue. |
Is this related to "Your Phone" app? I have a hard time allowing this app to connect to my phone. |
Mobile Hot-spot not work. 2019-...20...21 |
Some services need to enable internet access. Try allow this services in tab:
Some of them, i do not know what exactly, was required to correct working of Hotspot. |
Hi, I have the same problem. Cheers |
Simplewall not work with Hotspot. SW - Off and HS work |
I can confirm that even if I enable every rules, it still doesn't work and the firewall doesn't seem to detect the packets. |
This is a problem for those who use hotspot. I deleted the Simple for this. |
Recently my setup requires me to route all my Internet traffic through my Windows machine that was running simplewall for years. I love this piece of software, yet I had to let it go for Internet Sharing service to work properly. I would really love to see this issue resolved and continue using simplewall. |
+++ |
@henrypp I think there is some issue in allowing internet access to services, which is preventing hotspot from working. |
The hotspot network seems to be blocked even I turned off the filter until I rebooted the system and it worked again. The phone could access the host but could not reach beyond it. |
When I entirely disable the filters the hotspot internet access still blocked until I reboot the system, I think it's deep hidden code inside SW who prevent unexpected things or in (WFP) feature. I hope SW resolve this issue, because Mobile hotspot is very useful. |
i can get internet access through hotspot if i use the "disable filters" button without reboot but even if i allow every app, every service, every uwp app, every system rule, every user rule and allow blocklists for microsoft spying and telemetry/update/applications i cannot get internet through hotspot. |
@devdzt This is exactly what I observed too. @popdisk and @anwar-alsilwy Did you disable filters from SW, closing SW without disabling filters don't remove rules from WFP. |
@TontyTon , I disabled the filters and exit from SW completely, but the hotspot internet access never return until I reboot the whole system. |
@anwar-alsilwy Which version of windows you are on? |
@TontyTon I'm sure the SW filter as well as windows firewall disabled and all rules don't take effect, but the hotspot still not work. I'm using windows 10 21H2. |
@TontyTon, I'm using both builds W10 1909 & W10 21H2 |
I am having the same issue with the latest simplewall v3.6.1 Allowed this services:
Allowed this system rules:
but still hotspot has no internet access. Please help @henrypp |
hi everyone. Any solution on this subject yet? not able to share my internet with simplewall on. |
Not work Hotspot w Simplewall...and with Symantec Firewall, Hotspot not work too |
Quite sad this didn't receive much work oh well :/ |
I found a workaround. Disabling Windows Firewall fixed it for me, though you can immediately re-enable it if you want. However, if you subsequently toggle simplewall, the problem appears again. I suspect resetting the Windows Firewall refreshes some config. Maybe it's overwriting something that simplewall changed, or maybe just a bug in Windows, idk. When this issue was happening, I found a lot of lines in the simplewall.log file that look like this Pay attention to the filter description. If you look up the filter ID in Hopefully this helps somebody until there's a better fix. Maybe even help @henrypp debug the issue. |
After I tried the same thing with the Windows Defender Firewall, the Mobile hotspot still stucks in obtaining ip address. It seems be some problems in depth that does not relate with Simplewall. Add %SystemRoot%\System32\alg.exe to your whitelist may help. |
It's interesting to not see this feature implemented by default into Windows... The mobile hotspot is a great feature already, why not add some simple Allowlist-feature hmm |
indeed, but i disagree the second, the old ad-hoc wifi mode that was available in every windows version prior to windows10 was far superior than hotspot mode. And simplewall worked fine with it. since hotspot mode everything seems to be f* up with simplewall. |
Solution for hotspot to work you need to add (for win 10 at least):
and those are my rules: make sure to restart if there is connection to the device but no internet access more screnes: |
Are you able to block certain sites (blocklist) on the connected device? |
i tried this method yesterday, it was worked. But after im restarting my computer my wifi hotspot come back to "no internet access". i tried this method again several times, it's still not work. i wonder why also..... |
Yes i noticed that after some restart it will do not work while i was trying to check "block certain sites". The issue is in auto config and i did not found a solution. The best that i can recommend is to Hibernate pc and not shut it down for now. As to Hibernate im sure works fine. |
how can i make it work again? its okay if i need to do that per shutdown anw :" |
has anyone been able to fix this? It's a pity that in order to use this software, I have to completely give up the mobile hotspot function of windows. |
I heavily suggest to re-open this issue again, because it is actually NOT fixed. The mentioned "solutions" or "workarounds" here and there are all not suffiently working for different reasons. Some solutions seem to work only one-time and never work again if trying to reproduce. and the most basic point is, you can't seriously say any of these tinkersome, most-of-the-time-not-working workarounds are a solution to the problem. I'd assume the issue gets only closed, if the hotspot functionality works out of the box with simplewall or at least with a single checkbox to allow/disallow hotspot traffic, everything else is just a cheap and dirty, out of sight out of mind -solution. |
so thats it? mmkay.. |
So i found a workaround that works but has to be done everytime the PC is restarted, simply disable or enable windows firewall (If your firewall is disabled just re-enable it then disable it again), this should make the internet connection work |
It only works for 60 to 90 minutes on my PC. after that, I have to do it again. this workaround has some time limitation, I guess. |
I am using the Windows 10 builtin Hotspot to share my internet via WiFi. However, the hotspot does not work when I have the Simplewall filter on. I tried to allow all traffics through 192.168.0.0/16 by adding a rule but it doesn't work.
Does anyone know how to config Simplewall to make the hotspot work?
The text was updated successfully, but these errors were encountered: