Page 1 of 2 12 LastLast
Results 1 to 10 of 11
  1. #1
    Untanglit
    Join Date
    Mar 2011
    Posts
    19

    Default simple block ip rule not working

    I'm getting slammed by spammers and am trying to block their ip with a simple rule that should be a no-brainer.. but it's not showing up as a block even in the event log. What am I doing wrong? Please see attached screen shots.
    Thanks
    Attached Images Attached Images

  2. #2
    Untangle Ninja
    WebFooL's Avatar
    Join Date
    Jan 2009
    Location
    Sweden (Eskilstuna)
    Posts
    4,205

    Default

    You need to hit the "LOG" check box to see it in the event log.

  3. #3
    Untanglit
    Join Date
    Mar 2011
    Posts
    19

    Default

    ok. I did that, but it's still not blocking or logging. I'm watching the mailq on my server fill up with 100s of spams from this ip and it's not blocking.. What do you advise I do?

  4. #4
    Untangle Ninja
    WebFooL's Avatar
    Join Date
    Jan 2009
    Location
    Sweden (Eskilstuna)
    Posts
    4,205

    Default

    Try to make the rule more specific.
    Change Src interface to External.

    Have you any custom packet filter?

  5. #5
    Untanglit
    Join Date
    Mar 2011
    Posts
    19

    Default

    Ok. just tried that and still no cigar. See attached screen shot. When you say 'packet filter'.. I don't believe so.. other than what you see in my firewall rule set.
    Attached Images Attached Images

  6. #6
    Untanglit
    Join Date
    Mar 2011
    Posts
    19

    Default

    not using any custom packet filters.
    see also my port forwards
    See attached
    Attached Images Attached Images

  7. #7
    Untanglit
    Join Date
    Mar 2011
    Posts
    19

    Default

    Thanks WebFool.. I figured it out. I had a rule in there that was passing everything just to log all traffic.. oops :-) Now I feel dumb

  8. #8
    Untanglit
    Join Date
    Mar 2011
    Posts
    19

    Default

    WebFool,
    it sure would be nice to have some way to detect a lot of smtp traffic and block those ip's. Is there such a way to configure untangle to do that? We only have 6 users here and so we don't have a lot of mail traffic. I would think that there would be a way to do that and automate blocking ip's of spammers. Otherwise, I'm just going to have to continue to watch logs and notice lots of traffic and block ip's manually.
    Thanks

  9. #9
    Untanglit
    Join Date
    Mar 2011
    Posts
    19

    Default

    I'll just ask that question in another thread. Thanks again

  10. #10
    Untangle Ninja dwasserman's Avatar
    Join Date
    Jun 2008
    Location
    Argentina
    Posts
    3,998

    Default

    Do you have enable Tarpitting option in the anti spam settings?
    The world is divided into 10 kinds of people, who know binary and those not

Page 1 of 2 12 LastLast

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  

SEO by vBSEO 3.6.0 PL2