Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Blocking a specified IP - why smtp goes through?

    Scheduled Pinned Locked Moved Firewalling
    8 Posts 3 Posters 840 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • F Offline
      fips
      last edited by

      Hey!

      I added a simple firewall rule: block on WAN everything from that source ip.
      Tried it with my mobile phone, so i add the IP of my mobile phone to the rule and voila i couldn't reach my web servers behind the firewall.
      but funny fact, i CAN reach the mailserver via IMAP/SMTP.
      I moved the rule to the top but nothing changed.

      Public IP from webserver and public IP from the Mailserver are different, both are set up as IF Alias.

      Any Ideas?

      Thanks in advanced

      1 Reply Last reply Reply Quote 0
      • DerelictD Offline
        Derelict LAYER 8 Netgate
        last edited by

        Post your rules.  You're screwing something up somewhere.

        Chattanooga, Tennessee, USA
        A comprehensive network diagram is worth 10,000 words and 15 conference calls.
        DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
        Do Not Chat For Help! NO_WAN_EGRESS(TM)

        1 Reply Last reply Reply Quote 0
        • F Offline
          fips
          last edited by

          Here

          ![Screen Shot 2015-03-04 at 10.02.08.png](/public/imported_attachments/1/Screen Shot 2015-03-04 at 10.02.08.png)
          ![Screen Shot 2015-03-04 at 10.02.08.png_thumb](/public/imported_attachments/1/Screen Shot 2015-03-04 at 10.02.08.png_thumb)
          ![Screen Shot 2015-03-04 at 10.02.28.png](/public/imported_attachments/1/Screen Shot 2015-03-04 at 10.02.28.png)
          ![Screen Shot 2015-03-04 at 10.02.28.png_thumb](/public/imported_attachments/1/Screen Shot 2015-03-04 at 10.02.28.png_thumb)

          1 Reply Last reply Reply Quote 0
          • DerelictD Offline
            Derelict LAYER 8 Netgate
            last edited by

            Probably existing states after firewall changes.  Clear states if you want immediate satisfaction.

            Chattanooga, Tennessee, USA
            A comprehensive network diagram is worth 10,000 words and 15 conference calls.
            DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
            Do Not Chat For Help! NO_WAN_EGRESS(TM)

            1 Reply Last reply Reply Quote 0
            • F Offline
              fips
              last edited by

              Thanks for your reply.
              Well IMAP was blocked but SMTP still pass.
              So i investigated logs and found out that my gsm provider route the smtp traffic somehow over a different IP, which is of course not blocked.

              So everything is fine Thanks!  8)

              1 Reply Last reply Reply Quote 0
              • johnpozJ Offline
                johnpoz LAYER 8 Global Moderator
                last edited by

                what are you trying to do with that block rule on your wan?  You do understand that ALL inbound traffic is blocked on your wan, unless you have a port forward or firewall rule that allows it.  So what exactly did you think a rule that says hey block these source IPs is going to do other than the default rule that says hey block EVERTHING anyway??

                Do you have rules that would allow traffic to 25 that your not showing?

                An intelligent man is sometimes forced to be drunk to spend time with his fools
                If you get confused: Listen to the Music Play
                Please don't Chat/PM me for help, unless mod related
                SG-4860 25.07 | Lab VMs 2.8, 25.07

                1 Reply Last reply Reply Quote 0
                • F Offline
                  fips
                  last edited by

                  Sure, i have a lot of rules.
                  I just saw in log files that someone tries to probe few servers. So i blocked his IP.
                  All other services working like a charm.

                  1 Reply Last reply Reply Quote 0
                  • DerelictD Offline
                    Derelict LAYER 8 Netgate
                    last edited by

                    There is no difference between a specific rule blocking and a general rule blocking except, perhaps, quieting the log.

                    I, personally, let my firewall do it's job and don't play whack-a-mole.

                    Chattanooga, Tennessee, USA
                    A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                    DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                    Do Not Chat For Help! NO_WAN_EGRESS(TM)

                    1 Reply Last reply Reply Quote 0
                    • First post
                      Last post
                    Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.