• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

I'm having problem blocking IP-addresses from connecting to me

Scheduled Pinned Locked Moved Firewalling
6 Posts 4 Posters 2.6k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • G
    GeeZuZz
    last edited by Jun 6, 2007, 3:35 AM

    I'm trying to set up a blacklist of IP's that are not allowed to connect to our server, but i can't get it work.

    Here is what i do:
    Create alias "blacklist" and add networks like this:
    123.123.123.0 /24 <– should block from .1 to .254?

    Then i create a new rule, and place it underneath the "Block private networks" rule which is at top.
    Block, Protocoll: *, Source: blacklist, Dest.: *,  Port: *, Gateway: *

    In other words, i added a new rule like the "Block private networks", except it only blocks the alias called "blacklist".

    But i still get connections from 123.123.123.192 for instance. So what am i doing wrong?

    1 Reply Last reply Reply Quote 0
    • C
      cmb
      last edited by Jun 6, 2007, 5:02 AM

      What you're doing sounds correct, and works for me. It won't kill off existing states though, so if you're expecting it to cut off an active session, it won't.

      1 Reply Last reply Reply Quote 0
      • G
        GeeZuZz
        last edited by Jun 11, 2007, 1:00 AM

        Yes, i was thinking that too, but it was still getting new connections as well. :(

        1 Reply Last reply Reply Quote 0
        • J
          jahonix
          last edited by Jun 11, 2007, 6:49 AM

          Don't want to be picky, just verify my network knowledge…
          So correct me if I'm wrong:

          @GeeZuZz:

          123.123.123.0 /24 <– should block from .1 to .254?

          The net mask /24 should block from .0 to .255 including network and brodcast addresses, right?
          Anybody?

          Chris

          1 Reply Last reply Reply Quote 0
          • C
            cmb
            last edited by Jun 12, 2007, 3:00 AM

            @jahonix:

            Don't want to be picky, just verify my network knowledge…
            So correct me if I'm wrong:

            @GeeZuZz:

            123.123.123.0 /24 <– should block from .1 to .254?

            The net mask /24 should block from .0 to .255 including network and brodcast addresses, right?
            Anybody?

            That's correct.

            1 Reply Last reply Reply Quote 0
            • G
              GruensFroeschli
              last edited by Jun 12, 2007, 7:48 AM

              @GeeZuZz:

              Then i create a new rule, and place it underneath the "Block private networks" rule which is at top.
              Block, Protocoll: *, Source: blacklist, Dest.: *,  Port: *, Gateway: *

              that sounds to me as if you've added this rule on the LAN-tab.
              But rules on your LAN tab wont block connections comming from WAN to servers in your LAN.

              We do what we must, because we can.

              Asking questions the smart way: http://www.catb.org/esr/faqs/smart-questions.html

              1 Reply Last reply Reply Quote 0
              1 out of 6
              • First post
                1/6
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                This community forum collects and processes your personal information.
                consent.not_received