Results 1 to 7 of 7
  1. #1
    Untangler
    Join Date
    Oct 2009
    Posts
    82

    Exclamation Default block logging?

    Hi, I have the firewall setup so the default rule is block and I have all my open port rules. When this is enabled everything coming into my mail server or poeple accessing services on it is slow.

    Why?

    Also, with the default rule can I see what it is blocking? I was previously told that things blocked under the default block rule is not logged, is there a way to alter this.

    Thanks for your input.

  2. #2
    Untangle Ninja
    WebFooL's Avatar
    Join Date
    Jan 2009
    Location
    Sweden (Eskilstuna)
    Posts
    4,203

    Default

    Hi,
    what hardware are you running untangle on? (and what version and nr of users)

    i usaly have a block any any as the last rule and in that rule you can log.

  3. #3
    Untangler
    Join Date
    Oct 2009
    Posts
    82

    Default

    Quote Originally Posted by WebFooL View Post

    i usaly have a block any any as the last rule and in that rule you can log.
    What?

    And this is the setup

    Comcast----- untangle ----- exchange

    My untangle box:
    2 NICs
    3.33GHz Processor
    1 GB memory

    Thanks

  4. #4
    Untangle Ninja
    WebFooL's Avatar
    Join Date
    Jan 2009
    Location
    Sweden (Eskilstuna)
    Posts
    4,203

    Default

    to log all blockt traffic add a rule last in you firewall list.

    create that rule so it blocks traffic from any to any on port any to any.
    now all traffic that dose not go out over you pass rules will be blockt and logd.

  5. #5
    Untangler
    Join Date
    Oct 2009
    Posts
    82

    Default

    I don't think that's what I'm looking for, I put that as rule #17 and it does block everything, still. it overrides the rules above it

    i'm just trying to get it to have the rules (16) for open ports and then the rest blocked.

  6. #6
    Untangler
    Join Date
    Oct 2009
    Posts
    82

    Default

    I want to lock-down my network but for a few exceptions. What is the best way to do this?

    You can set the default behavior to block, as discussed in Firewall. Then, create a few rules to pass.
    If I do this it slows my OWA web access and web server access down a lot, why?

  7. #7
    Untangle Ninja
    WebFooL's Avatar
    Join Date
    Jan 2009
    Location
    Sweden (Eskilstuna)
    Posts
    4,203

    Default

    Also, with the default rule can I see what it is blocking? I was previously told that things blocked under the default block rule is not logged, is there a way to alter this.
    The only way to LOG all block traffic is to create a rule at the bottom.

    As the FW module reads the rule top to bottom try moving the pass rules for your OWA to the top.

    What other modules are you running?

Tags for this Thread

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  

SEO by vBSEO 3.6.0 PL2