Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Block all ports leave only the "basic needs" Because of P2P

    Scheduled Pinned Locked Moved Firewalling
    3 Posts 2 Posters 2.1k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • R
      rt_rex
      last edited by

      Hi i have a Box with 2 nics (LAn,WAN-PPPOe )
      I would like to close all ports on the firewall and leave only the ports for http(s),Messenger,ftp.(because of p2p,)
      I can disable the default rule on the LAN and set every thing by hand,in this case do i have to create the same rules on the WAN interface ?
      Or is there a better way to do this ?

      PS: i have snort running (once again because of P2P) and Captive Portal

      Don´t Try this @home go outside!
      WIFI Link @ 76 km
      Pfsense with 3G USB

      1 Reply Last reply Reply Quote 0
      • C
        cmb
        last edited by

        you enter rules on the interface the traffic originates. So to allow/deny traffic initiated from your LAN to the Internet, use LAN rules. To allow/deny inbound traffic initiated from the Internet, use WAN rules.

        1 Reply Last reply Reply Quote 0
        • R
          rt_rex
          last edited by

          Thanks what i was thinking.
          I having a bit of problem enabling msn video conference ports i looked around and found they are dinamyc and Microsoft recomends a huge port range.

          The actual Real-time Transport Protocol (RTP) streams are sent using dynamically allocated UDP ports in the range of 5004–65535. Without a way to open these UDP ports on any firewall in the path dynamically, the streams fail to reach their destination.

          From: http://technet.microsoft.com/en-us/library/b9bd86b1-a604-d747-b219-bb2ac5473e87.aspx#EKAA

          It was better to say leave every thing open :P

          Don´t Try this @home go outside!
          WIFI Link @ 76 km
          Pfsense with 3G USB

          1 Reply Last reply Reply Quote 0
          • First post
            Last post
          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.