Old 12-21-2011, 01:46 PM   #11 (permalink)
Master Untangler
 
Join Date: Apr 2008
Location: New Orleans, La
Posts: 103
johndball is on a distinguished road
Default

Fellas, unless there is something yall aren't sharing with me this is a default install less the rules that I have created and posted screenshots of.

What needs to be done to block all traffic for which a rule has not been created? This version of Untangle removes the option to block by default so please enlighten me.
Attached Images
File Type: png Untitled.png (19.0 KB, 12 views)
johndball is offline  
Old 12-21-2011, 01:53 PM   #12 (permalink)
Untangle Ninja
 
sky-knight's Avatar
 
Join Date: Apr 2008
Location: Phoenix, AZ
URLs submitted: 8
Posts: 15,454
sky-knight is on a distinguished road
Default

The firewall module cannot control traffic bound to Untangle anyway.

Where are you running that port scan from?

Because I can promise you, unless you've played with something, TCP 110 is NEVER open on Untangle. Nor is TCP 25.

You've done something to cause that read out, or your scan is lying to you.
__________________
Rob Sandling, BS:SWE, MCP
Intouch Technology
Phone: 480-272-9889
rob@intouchtechllc.com

UntangleAppliances.com
Phone: 866-794-8879
sky-knight is offline  
Old 12-21-2011, 01:55 PM   #13 (permalink)
Master Untangler
 
Join Date: Apr 2008
Location: New Orleans, La
Posts: 103
johndball is on a distinguished road
Default

Scanning from my house using SuperScan 3.0.

GRC shields up shows everything as stealth so I can't get an accurate reading from it.

I haven't changed anything I'm not familiar with. This is far from my first experience with Untangle. It is my first go around with the 9.x series and I haven't been pleased yet but since I'm stuck with 9.x I'd like to at least get it working correctly.

Edit: Look, I'm not trying to be an a$$hat as "emotions" aren't conveyed via text very well so don't interpret my postings as hostile.

Last edited by johndball; 12-21-2011 at 02:05 PM..
johndball is offline  
Old 12-21-2011, 02:30 PM   #14 (permalink)
Untangle Ninja
 
sky-knight's Avatar
 
Join Date: Apr 2008
Location: Phoenix, AZ
URLs submitted: 8
Posts: 15,454
sky-knight is on a distinguished road
Default

Don't worry about offending me, I'm all too aware of how cold text communication is. It's gotten me into piles of trouble around here.

If GRC shows everything stealth, and SuperScan does not, I think something it up with SuperScan.

That said, GRC should be reading TCP 443 open (remote admin, openvpn client distribution, etc) I suppose that port won't be open if you haven't installed any modules or never enabled remote admin.

And TCP 22 reads as closed without a packet filter rule to drop the traffic. Unless there is a new default that fixes that. But those are seriously the only two ports that show anything other than "I'm not here" by default.
__________________
Rob Sandling, BS:SWE, MCP
Intouch Technology
Phone: 480-272-9889
rob@intouchtechllc.com

UntangleAppliances.com
Phone: 866-794-8879
sky-knight is offline  
Old 12-21-2011, 02:31 PM   #15 (permalink)
Untangle Ninja
 
sky-knight's Avatar
 
Join Date: Apr 2008
Location: Phoenix, AZ
URLs submitted: 8
Posts: 15,454
sky-knight is on a distinguished road
Default

Heck, test it yourself!

telnet external.ip.of.untangle 80

That will open a connection to your Untangle on port 80, does it time out?
__________________
Rob Sandling, BS:SWE, MCP
Intouch Technology
Phone: 480-272-9889
rob@intouchtechllc.com

UntangleAppliances.com
Phone: 866-794-8879
sky-knight is offline  
Old 12-21-2011, 02:46 PM   #16 (permalink)
Master Untangler
 
Join Date: Apr 2008
Location: New Orleans, La
Posts: 103
johndball is on a distinguished road
Default

Is the packet filter portion of Untangle all pre-NAT related rules?
Do they process in order from top down?
johndball is offline  
Old 12-21-2011, 03:18 PM   #17 (permalink)
Untangle Ninja
 
sky-knight's Avatar
 
Join Date: Apr 2008
Location: Phoenix, AZ
URLs submitted: 8
Posts: 15,454
sky-knight is on a distinguished road
Default

Yes, to both questions as far as I know.
__________________
Rob Sandling, BS:SWE, MCP
Intouch Technology
Phone: 480-272-9889
rob@intouchtechllc.com

UntangleAppliances.com
Phone: 866-794-8879
sky-knight is offline  
Old 12-21-2011, 03:20 PM   #18 (permalink)
Master Untangler
 
Join Date: Apr 2008
Location: New Orleans, La
Posts: 103
johndball is on a distinguished road
Default

So, if I wanted "firewall" pre-nat rules I would do so in the packet filter? Since all is now allow by default I would need to set rules to block pre-nat essentially using the packet filter as a pre-nat firewall.
johndball is offline  
Old 12-21-2011, 03:43 PM   #19 (permalink)
Untangle Ninja
 
sky-knight's Avatar
 
Join Date: Apr 2008
Location: Phoenix, AZ
URLs submitted: 8
Posts: 15,454
sky-knight is on a distinguished road
Default

No, the packet filter is block by default. The firewall module is pass by default.

But yes you have to use the packet filter to control traffic that is terminating on the Untangle server itself.
__________________
Rob Sandling, BS:SWE, MCP
Intouch Technology
Phone: 480-272-9889
rob@intouchtechllc.com

UntangleAppliances.com
Phone: 866-794-8879
sky-knight is offline  
Old 12-21-2011, 04:20 PM   #20 (permalink)
Master Untangler
 
Join Date: Apr 2008
Location: New Orleans, La
Posts: 103
johndball is on a distinguished road
Default

Done. I got it working so that all is blocked except what I open up both pre and post NAT.
johndball is offline  
Closed Thread

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 06:33 AM.


© 2010 Untangle, Inc. All Rights Reserved.   SEO by vBSEO 3.6.0 PL2