Old 12-11-2011, 02:32 PM   #1 (permalink)
Master Untangler
 
7echno7im's Avatar
 
Join Date: Feb 2009
URLs submitted: 1
Posts: 169
7echno7im is on a distinguished road
Default Firewall not blocking ports

I have external administration on, but I want to block 22 still. Is this possible? I don't recall my ssh port being wide open before the upgrade even though I had external admin on (for https).

I tried to follow the wiki example the best I could but it is outdated.

It seems no matter how I slice it, 22 is open to the pub.
Attached Images
File Type: png Capture.PNG (26.5 KB, 11 views)
__________________
www.techtronic.us

Last edited by 7echno7im; 12-11-2011 at 02:36 PM..
7echno7im is offline  
Old 12-11-2011, 02:36 PM   #2 (permalink)
Master Untangler
 
7echno7im's Avatar
 
Join Date: Feb 2009
URLs submitted: 1
Posts: 169
7echno7im is on a distinguished road
Default

The attachment is wrong and I cant edit it.
__________________
www.techtronic.us
7echno7im is offline  
Old 12-11-2011, 02:37 PM   #3 (permalink)
Master Untangler
 
7echno7im's Avatar
 
Join Date: Feb 2009
URLs submitted: 1
Posts: 169
7echno7im is on a distinguished road
Default

Capture.PNG
__________________
www.techtronic.us
7echno7im is offline  
Old 12-11-2011, 02:41 PM   #4 (permalink)
Master Untangler
 
7echno7im's Avatar
 
Join Date: Feb 2009
URLs submitted: 1
Posts: 169
7echno7im is on a distinguished road
Default

Is it just me or did the "Source Port" option go away in 9.1?
__________________
www.techtronic.us
7echno7im is offline  
Old 12-11-2011, 03:33 PM   #5 (permalink)
Untangle Junkie
 
dmorris's Avatar
 
Join Date: Nov 2006
Location: San Mateo, CA
URLs submitted: 10
Posts: 10,611
dmorris is on a distinguished road
Default

Firewall doesn't process traffic to/from the untangle server, just traffic going *through* the untangle server. If you don't want port 22 open, I'd just disable SSH.
If you don't want it to show as closed, you can go into config->networking->advanced->packet filter and at the bottom uncheck "Allow SSH from all interfaces."

btw, No point in adding matchers to rules that just match on "any." You might as well remove them since they always match.

Yes, source port went away.
I bet you noticed that when you tried to add a matcher to set source port = 22, right?
__________________
Attention: Support and help on the Untangle Forums is provided by
volunteers and community members like yourself.
If you need Untangle support please call or email support@untangle.com

Last edited by dmorris; 12-11-2011 at 03:40 PM..
dmorris is offline  
Old 12-11-2011, 08:24 PM   #6 (permalink)
Master Untangler
 
7echno7im's Avatar
 
Join Date: Feb 2009
URLs submitted: 1
Posts: 169
7echno7im is on a distinguished road
Default

Awesome thank you. Sorry I should have remembered about the packet filter. Honestly, Untangle has run so well for so long I haven't had to adjust any of this. It truly has been set it and forget it. I still want ssh internally, just not exposed to the public so I created a user packet filter rule. Works like a charm.

I did notice the source port went away when trying to make the FW rule

thanks for the help.
__________________
www.techtronic.us
7echno7im is offline  
Closed Thread

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 06:31 AM.


© 2010 Untangle, Inc. All Rights Reserved.   SEO by vBSEO 3.6.0 PL2