Go Back   Untangle Forums > General Forums > Tip of the Day!

Reply
 
LinkBack Thread Tools
Old 03-01-2008, 05:29 PM   #1 (permalink)
Untangle Ninja
 
Silver Bullet's Avatar
 
Join Date: Sep 2007
URLs submitted: 3
Posts: 1,981
Default How To: Block sites accessed by IP Address

I have seen a couple forum topics asking about blocking sites that are accessed by it's IP address to get around the Web Filter. Well, here is how this is done using the Protocol Control module.

Click Show Settings on the Protocol Control Module.

Select the Protocol List tab

Click the green + sign to create a new rule.

You should have a new line appear green in the rules list.

In the Category cell, enter Block Access by IP

In the Protocol Cell, enter Access by IP

Check the Block and check the Log cells

In the Description Cell, enter Block requests made with IP address

In the Signature Cell, enter
Code:
(GET|POST|HEAD) [^ ]+ HTTP.*host: \b\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3}\b
Click Save

Now try to access a site by it's IP address. You should get a blank page and an Event should show up as blocked in the Protocol Control module's Event Log.

I have tested this and it seems to work fine. What that signature does is checks the "host" field in the request and if it contains an IP address in an http request, then it blocks it.

Have Fun enforcing the Web Filter!!

Thanks Seb for helping me fine tune it.

Last edited by Silver Bullet; 03-01-2008 at 07:54 PM.. Reason: Edited rule
Silver Bullet is offline   Reply With Quote
Old 03-01-2008, 07:59 PM   #2 (permalink)
Untangle Ninja
 
Silver Bullet's Avatar
 
Join Date: Sep 2007
URLs submitted: 3
Posts: 1,981
Default

Edited the signature in the original post so that it should only apply to HTTP traffic.
Silver Bullet is offline   Reply With Quote
Old 03-03-2008, 07:26 AM   #3 (permalink)
mdh
Super Moderator
 
mdh's Avatar
 
Join Date: Aug 2007
URLs submitted: 171
Posts: 3,757
Default

HOT STUFF!
mdh is offline   Reply With Quote
Old 03-04-2008, 09:58 AM   #4 (permalink)
Newbie
 
Join Date: Mar 2008
Posts: 1
Default

Thank you for sharing this tip. It works great!
tcbroonsie is offline   Reply With Quote
Old 03-04-2008, 01:31 PM   #5 (permalink)
Untanglit
 
MSoucy's Avatar
 
Join Date: Sep 2007
URLs submitted: 29
Posts: 23
Default

Thank YOU!

One more step closer to only having one box for my firewall/filter
MSoucy is offline   Reply With Quote
Old 03-04-2008, 05:11 PM   #6 (permalink)
Untangle Ninja
 
Silver Bullet's Avatar
 
Join Date: Sep 2007
URLs submitted: 3
Posts: 1,981
Default

Quote:
Originally Posted by MSoucy View Post
Thank YOU!

One more step closer to only having one box for my firewall/filter
What else is keeping you?
Silver Bullet is offline   Reply With Quote
Old 05-01-2008, 02:34 PM   #7 (permalink)
Untanglit
 
Join Date: Mar 2008
Posts: 13
Default

Thanks. Just what I needed.
IA76 is offline   Reply With Quote
Old 05-06-2008, 03:47 AM   #8 (permalink)
Untanglit
 
fartman's Avatar
 
Join Date: Mar 2008
Posts: 26
Default

Thanks, tested in 5.10 and it works.
fartman is offline   Reply With Quote
Old 05-06-2008, 05:59 AM   #9 (permalink)
Master Untangler
 
Ron Chandy's Avatar
 
Join Date: Feb 2008
Posts: 117
Default

"WOW" silver Bullet that was great stuff. IS there a system to block email addresses also. I have started a thresd on it..
__________________
No defeat is final untill you give-up trying,
Ron Chandy is offline   Reply With Quote
Old 05-12-2008, 12:52 PM   #10 (permalink)
Untangler
 
Join Date: Apr 2008
URLs submitted: 2
Posts: 87
Default


Thank you for this. Infact back in school I used to get around the filters by using IPs so this is great.
impmonkey is offline   Reply With Quote
Reply

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 06:42 AM.


© 2009 Untangle, Inc. All Rights Reserved.   SEO by vBSEO 3.2.0