Old 04-30-2009, 09:27 PM   #1 (permalink)
Master Untangler
 
Join Date: Oct 2008
Posts: 140
yuanyudistira is on a distinguished road
Default Firewall setup example

Dear all

Is there anyone here can share or help me setting up firewall?

I only will allow browsing internet, access email, ftp for some client.
others applications should not go to internet.

And regarding email, only my email server is able to send email.
PC from my network should not send email (probably virus / spyware)

Please help


Thanks

YUAN
yuanyudistira is offline  
Old 04-30-2009, 11:18 PM   #2 (permalink)
Untangle Junkie
 
dmorris's Avatar
 
Join Date: Nov 2006
Location: San Mateo, CA
URLs submitted: 10
Posts: 10,611
dmorris is on a distinguished road
Default

just set to the default rule to block, then add all the ports you would like to pass in a rule.

port 53 for DNS, 80 for web, etc.
__________________
Attention: Support and help on the Untangle Forums is provided by
volunteers and community members like yourself.
If you need Untangle support please call or email support@untangle.com
dmorris is offline  
Old 04-30-2009, 11:26 PM   #3 (permalink)
Master Untangler
 
Join Date: Oct 2008
Posts: 140
yuanyudistira is on a distinguished road
Default

Thanks for your reply,

But do you have a list of common port that I should know?

YUAN

Quote:
Originally Posted by dmorris View Post
just set to the default rule to block, then add all the ports you would like to pass in a rule.

port 53 for DNS, 80 for web, etc.
yuanyudistira is offline  
Old 05-01-2009, 12:24 AM   #4 (permalink)
Untangle Ninja

 
WebFooL's Avatar
 
Join Date: Jan 2009
Location: Sweden (Eskilstuna)
URLs submitted: 57
Posts: 3,877
WebFooL is on a distinguished road
Send a message via MSN to WebFooL
Default

Hi,

Allow FTP
Code:
Enable Rule: Yes
Description: Allow FTP 21 
Action: Pass
Log: Up to you
Rule
Traffic Type: TCP AND UDP
Source Interface: Internal
Destination Interface: External
Source Address: any (or limit by 192.168.10.2,192.168.10.5)
Destination Address: any
Source Port: any
Destination Port: 21
Allow DNS:
Code:
Enable Rule: Yes
Description: Allow DNS 53
Action: Pass
Log: Up to you
Rule
Traffic Type: TCP AND UDP
Source Interface: Internal
Destination Interface: External
Source Address: any
Destination Address: any
Source Port: any
Destination Port: 53
HTTP Port 80:
Code:
Enable Rule: Yes
Description: Allow Port 80 HTTP
Action: Pass
Log: Up to you
Rule
Traffic Type: TCP AND UDP
Source Interface: Internal
Destination Interface: External
Source Address: any
Destination Address: any
Source Port: any
Destination Port: 80
HTTPS Port 443:
Code:
Enable Rule: Yes
Description: Allow Port 443 HTTP
Action: Pass
Log: Up to you
Rule
Traffic Type: TCP AND UDP
Source Interface: Internal
Destination Interface: External
Source Address: any
Destination Address: any
Source Port: any
Destination Port: 443
Read this thread on how to only allow one ip to send SMTP traffic
http://forums.untangle.com/networkin...il-server.html

for port numbers you can use:
http://www.iana.org/assignments/port-numbers
WebFooL is offline  
Old 05-30-2009, 07:51 AM   #5 (permalink)
Untanglit
 
Join Date: May 2009
Posts: 22
running is on a distinguished road
Default

This is interesting, i was looking for this kind of info to. I have a bit more question

If i select block all and had those rules but i am also running a mail server do i need to put other rules?

Is open VPN in need of something special?

Thank you i advance
running is offline  
Old 06-03-2009, 06:48 PM   #6 (permalink)
Untanglit
 
Join Date: May 2009
Posts: 22
running is on a distinguished road
Default

Anyone with an idea?
running is offline  
Old 06-11-2009, 05:20 AM   #7 (permalink)
Untanglit
 
Join Date: Jun 2009
Posts: 27
3minds is on a distinguished road
Default

If i select block all and had those rules but i am also running a mail server do i need to put other rules?

Yes, add the POP and SMTP ports and select it only for your mail server if other computer is not allowed to send mail. Otherwise, accept for the internal source

Yes, for openVPN, you need to set some rules. You can follow this tutorial

http://www.vancocomputing.com/blogs/...configuration/

Good luck

Last edited by 3minds; 06-11-2009 at 05:30 AM..
3minds is offline  
Old 06-11-2009, 07:43 PM   #8 (permalink)
Untanglit
 
Join Date: May 2009
Posts: 22
running is on a distinguished road
Default

thank you!
running is offline  
Old 07-06-2009, 07:38 AM   #9 (permalink)
Newbie
 
Join Date: Jul 2009
Posts: 1
maxim is on a distinguished road
Default

Thank you for this thread. It was very helpful!
maxim is offline  
Old 10-19-2009, 03:58 AM   #10 (permalink)
Untangler
 
Join Date: Oct 2008
Posts: 80
kirkcaine is on a distinguished road
Default

keep for notes
kirkcaine is offline  
Closed Thread

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


LinkBacks (?)
LinkBack to this Thread: http://forums.untangle.com/firewall/9060-firewall-setup-example.html
Posted By For Type Date
Firewall-setup-example---Untangle-Forums This thread Refback 04-06-2011 12:07 AM


All times are GMT -7. The time now is 06:55 AM.


© 2010 Untangle, Inc. All Rights Reserved.   SEO by vBSEO 3.6.0 PL2