Results 1 to 5 of 5
  1. #1
    Newbie
    Join Date
    Jul 2018
    Posts
    11

    Default Try to block countries

    Hi,
    I try to block incommig connection from some countries and to some ports (port forwarded ton rdp server by example)
    In application/firewall I setup the following rules, but none connection are blocked

    untangle-countries.PNG

  2. #2
    Untangler jcoffin's Avatar
    Join Date
    Aug 2008
    Location
    Sunnyvale, CA
    Posts
    7,671

    Default

    How do you know the connection is not blocked? Look at the reports.
    Attention: Support and help on the Untangle Forums is provided by
    volunteers and community members like yourself.
    If you need Untangle support please call or email support@untangle.com

  3. #3
    Newbie
    Join Date
    Jul 2018
    Posts
    11

    Default

    HI,
    Your right. I'm confusing events/alerts events where a found "suspicious activity" with the Ip adress from countries present in my firewall rules and the firewall/blocked events where I found the same IP blocked.
    Then I think the rule for blocking some countries is welle functionning.
    But why if an ip is blocked by the firewall rule the alert is present as suspicious activity ?
    I'll also try to tag with events/trigers some suspicious activities but also the tag is not present in the log ...But I'll open a other ticket for this issue

  4. #4
    Untangle Ninja sky-knight's Avatar
    Join Date
    Apr 2008
    Location
    Phoenix, AZ
    Posts
    23,234

    Default

    Quote Originally Posted by frdt View Post
    HI,
    Your right. I'm confusing events/alerts events where a found "suspicious activity" with the Ip adress from countries present in my firewall rules and the firewall/blocked events where I found the same IP blocked.
    Then I think the rule for blocking some countries is welle functionning.
    But why if an ip is blocked by the firewall rule the alert is present as suspicious activity ?
    I'll also try to tag with events/trigers some suspicious activities but also the tag is not present in the log ...But I'll open a other ticket for this issue
    The rack applications all scan traffic alongside each other. So yes, you're going to see the firewall block things while say application control checks it too. That's normal.
    Rob Sandling, BS:SWE, MCP
    NexgenAppliances.com
    Phone: 866-794-8879 x201
    Email: support@nexgenappliances.com

  5. #5
    Newbie
    Join Date
    Mar 2019
    Posts
    13

    Default

    Would be great to have a more intuitive way to do this.

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  

SEO by vBSEO 3.6.0 PL2