|
Hi, I'm having an issue trying to get the DLNA integration to discover my sonos system and I've figured out it's due to my firewall, but I'm not sure what I should do to allow things to work. I'm on cachy-os (arch) and running ufw firewall with default outgoing policy "Allow" and default incoming policy "Ignore". If I disable ufw I can click the DLNA button in feishin and it discovers and plays to my sonos devices, but when the firewall is turned on, it cannot even discover the DLNA devices on the network. Is this expected behavior? Are there specific ports I can allow through the firewall to make it work without disabling it? Also is this something the feishin package can ship with (a ufw config file with preconfigured ports)? Thanks! |
Replies: 1 comment 1 reply
|
Yes, it is expected with a default-deny incoming policy, and the fix is to allow incoming traffic from the speakers' addresses. Discovery cannot be opened with a port rule, because both ends of the exchange use random ports. Discovery sends an SSDP search to the multicast address So allow the speakers themselves: Give the speakers fixed addresses (DHCP reservations) so the rules keep matching, or allow the whole LAN with The same rules cover the other incoming connections Feishin uses. On Linux it starts an HTTP server with I reproduced it with the same socket code as
About shipping a UFW profile: a profile in |
Yes, it is expected with a default-deny incoming policy, and the fix is to allow incoming traffic from the speakers' addresses. Discovery cannot be opened with a port rule, because both ends of the exchange use random ports.
Discovery sends an SSDP search to the multicast address
239.255.255.250:1900from a socket bound to port 0, so the kernel picks a random port each time (src/main/features/core/dlna/ssdp-discovery.ts). Each speaker answers with a unicast packet from its own IP to that random port. Connection tracking cannot link that answer to the search, because the search went to the multicast address and the answer comes from a different one, so UFW sees a new incoming packet and dr…