Results 1 to 2 of 2
  1. #1
    Newbie
    Join Date
    Aug 2019
    Posts
    2

    Default Region blocking not stopping EXTERNAL->WAN

    Assuming this is a misconfiguration on my end, but I have 2 rules set up to block regions:

    untangle-region-block-client.PNG
    untangle-region-block-server.PNG

    The server rule works fine; I actually found out one of my android tablets still had ES File Explorer installed on it which turned into Chinese malware back in 2017. However I still get IPS hits from external to my WAN address and the client rule is never flagged in my firewall report. Below is a signature hit from a Russian IPs as they showed up in my IPS report.

    2500066.PNG

    I've found other Chinese and Russian IPs in my IPS logs too besides this one so I'm curious if I've configured something wrong or if this is expected behavior. Both rules are at the top of my firewall priority so I'm not sure what I'm doing wrong. Thanks in advance for any advice!

  2. #2
    Untangler jcoffin's Avatar
    Join Date
    Aug 2008
    Location
    Sunnyvale, CA
    Posts
    8,163

    Default

    Connections to the External IP are blocked using access rules. /admin/index.do#config/network/advanced

    https://wiki.untangle.com/index.php/Access_Rules
    Attention: Support and help on the Untangle Forums is provided by
    volunteers and community members like yourself.
    If you need Untangle support please call or email support@untangle.com

Tags for this Thread

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  

SEO by vBSEO 3.6.0 PL2