Old 03-01-2008, 05:29 PM   #1 (permalink)
Untangle Ninja
 
Silver Bullet's Avatar
 
Join Date: Sep 2007
URLs submitted: 3
Posts: 2,008
Silver Bullet is on a distinguished road
Default How To: Block sites accessed by IP Address

I have seen a couple forum topics asking about blocking sites that are accessed by it's IP address to get around the Web Filter. Well, here is how this is done using the Protocol Control module.

Click Show Settings on the Protocol Control Module.

Select the Protocol List tab

Click the green + sign to create a new rule.

You should have a new line appear green in the rules list.

In the Category cell, enter Block Access by IP

In the Protocol Cell, enter Access by IP

Check the Block and check the Log cells

In the Description Cell, enter Block requests made with IP address

In the Signature Cell, enter
Code:
(GET|POST|HEAD) [^ ]+ HTTP.*host: \b\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3}\b
Click Save

Now try to access a site by it's IP address. You should get a blank page and an Event should show up as blocked in the Protocol Control module's Event Log.

I have tested this and it seems to work fine. What that signature does is checks the "host" field in the request and if it contains an IP address in an http request, then it blocks it.

Have Fun enforcing the Web Filter!!

Thanks Seb for helping me fine tune it.

Last edited by Silver Bullet; 03-01-2008 at 07:54 PM.. Reason: Edited rule
Silver Bullet is offline  
Old 03-01-2008, 07:59 PM   #2 (permalink)
Untangle Ninja
 
Silver Bullet's Avatar
 
Join Date: Sep 2007
URLs submitted: 3
Posts: 2,008
Silver Bullet is on a distinguished road
Default

Edited the signature in the original post so that it should only apply to HTTP traffic.
Silver Bullet is offline  
Old 03-03-2008, 07:26 AM   #3 (permalink)
mdh
Untangle Ninja
 
mdh's Avatar
 
Join Date: Aug 2007
URLs submitted: 171
Posts: 4,802
mdh is on a distinguished road
Default

HOT STUFF!
mdh is offline  
Old 03-04-2008, 09:58 AM   #4 (permalink)
Newbie
 
Join Date: Mar 2008
Posts: 1
tcbroonsie is on a distinguished road
Default

Thank you for sharing this tip. It works great!
tcbroonsie is offline  
Old 03-04-2008, 01:31 PM   #5 (permalink)
Untanglit
 
MSoucy's Avatar
 
Join Date: Sep 2007
URLs submitted: 29
Posts: 25
MSoucy is on a distinguished road
Default

Thank YOU!

One more step closer to only having one box for my firewall/filter
MSoucy is offline  
Old 03-04-2008, 05:11 PM   #6 (permalink)
Untangle Ninja
 
Silver Bullet's Avatar
 
Join Date: Sep 2007
URLs submitted: 3
Posts: 2,008
Silver Bullet is on a distinguished road
Default

Quote:
Originally Posted by MSoucy View Post
Thank YOU!

One more step closer to only having one box for my firewall/filter
What else is keeping you?
Silver Bullet is offline  
Old 05-01-2008, 02:34 PM   #7 (permalink)
Newbie
 
Join Date: Mar 2008
Posts: 14
IA76 is on a distinguished road
Default

Thanks. Just what I needed.
IA76 is offline  
Old 05-06-2008, 03:47 AM   #8 (permalink)
Untangler
 
fartman's Avatar
 
Join Date: Mar 2008
Posts: 58
fartman is on a distinguished road
Default

Thanks, tested in 5.10 and it works.
fartman is offline  
Old 05-06-2008, 05:59 AM   #9 (permalink)
Master Untangler
 
Ron Chandy's Avatar
 
Join Date: Feb 2008
Posts: 134
Ron Chandy is on a distinguished road
Default

"WOW" silver Bullet that was great stuff. IS there a system to block email addresses also. I have started a thresd on it..
__________________
I believe in Angels...
Ron Chandy is offline  
Old 05-12-2008, 12:52 PM   #10 (permalink)
Master Untangler
 
Join Date: Apr 2008
URLs submitted: 3
Posts: 136
impmonkey is on a distinguished road
Default


Thank you for this. Infact back in school I used to get around the filters by using IPs so this is great.
impmonkey is offline  
Closed Thread

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 10:13 AM.


© 2010 Untangle, Inc. All Rights Reserved.   SEO by vBSEO 3.6.0 PL2