Old 10-16-2011, 12:55 AM   #1 (permalink)
Newbie
 
Join Date: Oct 2010
Posts: 12
ellocomoco is on a distinguished road
Default Want to block all ports except 80 and 443

I have a policy (see attachment) blocking port 0-79, 81-442, and 444-65535. It works great on blocking, but it is time consuming try to open another port the way I made this policy. Can someone advise me on an easier solution?
Attached Images
File Type: jpg Port Block.JPG (16.9 KB, 28 views)
File Type: jpg Port Block 2.JPG (30.0 KB, 51 views)
ellocomoco is offline  
Old 10-16-2011, 02:00 AM   #2 (permalink)
Master Untangler
 
Join Date: Feb 2009
Posts: 145
fslomka is on a distinguished road
Default

That is very simple use the "Firewall App" and set "Default Action" to Block

All you have to do then is to set "Pass Rules"
fslomka is offline  
Old 10-16-2011, 02:36 AM   #3 (permalink)
Untangle Ninja
 
sky-knight's Avatar
 
Join Date: Apr 2008
Location: Phoenix, AZ
URLs submitted: 8
Posts: 15,454
sky-knight is on a distinguished road
Default

That default action is going away in the future.

The Firewall module blocks or passes things on a first rule match wins ideology.

So make a general block rule that blocks everything, and just make sure your pass rules are above it. You don't need to fit everything into a single firewall rule.
__________________
Rob Sandling, BS:SWE, MCP
Intouch Technology
Phone: 480-272-9889
rob@intouchtechllc.com

UntangleAppliances.com
Phone: 866-794-8879
sky-knight is offline  
Old 10-16-2011, 09:27 AM   #4 (permalink)
Untangle Junkie
 
dmorris's Avatar
 
Join Date: Nov 2006
Location: San Mateo, CA
URLs submitted: 10
Posts: 10,611
dmorris is on a distinguished road
Default

Quote:
Originally Posted by ellocomoco View Post
I have a policy (see attachment) blocking port 0-79, 81-442, and 444-65535. It works great on blocking, but it is time consuming try to open another port the way I made this policy. Can someone advise me on an easier solution?
That rule won't work unless you set source port to "any"
__________________
Attention: Support and help on the Untangle Forums is provided by
volunteers and community members like yourself.
If you need Untangle support please call or email support@untangle.com
dmorris is offline  
Old 10-17-2011, 11:38 AM   #5 (permalink)
Newbie
 
Join Date: Oct 2010
Posts: 12
ellocomoco is on a distinguished road
Default Block all except 80 & 443

sky-knight,

I tried your idea and I am having trouble with it. It seems to still pass all traffic. Please see my attachments and let me know what I am doing wrong.
Attached Images
File Type: jpg Firewall Policy1.JPG (26.9 KB, 33 views)
File Type: jpg HTTP HTTPS Rule.JPG (26.3 KB, 42 views)
File Type: jpg Block All.JPG (26.2 KB, 44 views)
ellocomoco is offline  
Old 10-17-2011, 11:44 AM   #6 (permalink)
Untangle Junkie
 
dmorris's Avatar
 
Join Date: Nov 2006
Location: San Mateo, CA
URLs submitted: 10
Posts: 10,611
dmorris is on a distinguished road
Default

Quote:
Originally Posted by dmorris View Post
That rule won't work unless you set source port to "any"
If it helps, just assume that a rule with "source port" is set to anything besides ANY is effectively disabled.

edit:
and you probably want to allow DNS traffic unless they are using the untangle server itself for DNS.
__________________
Attention: Support and help on the Untangle Forums is provided by
volunteers and community members like yourself.
If you need Untangle support please call or email support@untangle.com

Last edited by dmorris; 10-17-2011 at 11:52 AM..
dmorris is offline  
Closed Thread

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 06:20 AM.


© 2010 Untangle, Inc. All Rights Reserved.   SEO by vBSEO 3.6.0 PL2