News: This forum is now permanently frozen.
Pages: [1]
Topic: Fire wall rules, driving me nuts.  (Read 1713 times)
« on: March 07, 2008, 10:06:39 »
Franscois *
Posts: 4

Hi all
I am in china and there are so many programs out there that do streaming video and audio on the net here that it is very hard to keep on top of it.
So I have decided that I will block all ports and only open the ones that are needed for:
HTTP, DNS, POP3, SMTP, Yahoo, Skype.
The reason for me opening yahoo and Skype is because we need it for international communication.

Here is my setup:
I have 2 gigabit Lan cards on the fire wall one for Lan and one for wan.
I have a 4 MB fiber optic internet line hooked up to the wan.
I need to block every thinks except the above mentioned things.
If anyone knows how to do this and can supply me with a bit more detail that is available on the site pleas reply or email me directly.
It will be greatly appreciated and if I figer it out I will make a detailed help file including images for for this topic
And post it here on the forum.  Wink
« Reply #1 on: March 25, 2008, 16:41:53 »
markb ****
Posts: 331

This is a fairly simple thing to do.  the main thing to remember, is to have your rules in the correct order with the block rule at the bottom of the list.

Firstly identify the ports you want to open.
http, dns, pop3 & SMTP are all selectable by name in the rules page.  You might want to include https and ntp as well.  Yahoo and Skype will I believe all use port 80 quite happily.

Next create your rules, they will all look fairly similar.
Action   Interface     Protocol     Source     Port     Destination    Port
Pass      LAN             TCP              Any         Any      Any                http
Pass      LAN             TCP              Any         Any      Any                https
Pass      LAN           TCP/udp         Any         Any      Any                DNS
Pass      LAN             TCP              Any         Any      Any                SMTP
Pass      LAN             TCP              Any         Any      Any                POP
Pass      LAN             UDP              Any        Any      Any                123

Block      LAN             Any               Any       Any       Any                Any

Hope this helps.
 
Pages: [1]
 
 
Powered by SMF 1.1.20 | SMF © 2013, Simple Machines