Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations Chris Miller on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Deny Specific IP Adresses access through the firewall 1

Status
Not open for further replies.

bond5512

MIS
Jul 31, 2002
1
US
Is there a way to turn on and manually add an ip address to the blacklist in raptor. I have several IP address I would like to block that do not meet the criteria for an attack. If I change the connetion settings to be less than what they are now, I will affect legitimate users.
 
1) create an entity with the IP address of the system you want to deny access.

2) create a new rule which denies access from source "entity" ( the entity you created in step 1) to "universe".

3) save configuration
 
How would I do the same with a port? I want to block instant messaging server and port access from my network. Thank you
 
1) create a new protocol with the port which is used by instant messaging (i don't know the port number but if you start instant messaging you can look it up in the log file).

2) create a new rule which denies access from "universe" to "universe" to the newly created "instant messaging protocol".

3)save configuration

 
I tried what Rene said re:blocking ips with my own web page to see if it'd work. For the entity I used the ip of my house.

Made a rule denying from source (my entity) to universe (on any interfaces). For services I did all*, http* and others. Saved. But I can still pull up my web page from my desk.

The radius settings for my account are "full-access" but shouldn't that still block it? I tried flipping the from and to roles but no go. Any ideas? thanks much.
 
You must do it the other way around, deny access from "*universe to my_entity" instead of from "my_entity to *universe".
 
I've tried it both ways, my page still loads faster then cash into a whiplash attourney's Swiss bank account.



For services, I have included almost every service in the book. I have the in/out interfaces set for "any", that should be ok right?



It's not a cached copy, sometimes it seems like it's not working (the server is slow) but I'm able to add/read content, run code, etc
 
I think there must be something wrong with the entity you created. You can check this by creating a deny rule:

from *universe to *universe, protocol *all

be carefull with this rule, it will block all traffice !

if you can't load the page anymore with this rule in place, then there is something wrong with your entity
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top