News: This forum is now permanently frozen.
Pages: [1]
Topic: Making firewall rules to block ranges of IP-s  (Read 3005 times)
« on: July 24, 2007, 18:51:58 »
SpelingMistakes *
Posts: 4

I lead forum for a while – I am not so sophisticated expert in networking, but I do that with my knowledge and all work good – till now Smiley I want to improve some things in case of security.

Now I have got my hands on VmWare version of monowall and I want to setup it right. I have next situation – I have my own server and on it I have VmServer – with two virtual machines. (Monowall is third) I want to make much more secure using of my servers (virtual). I already set up monowall (small problems in the beginning) and it work like a rooter simply allowing form one real pc (my) to connect to the internet trough monowall.

Now I want to set up some rules in case of firewall. I didn’t find simple way to block some hackers from Taiwan or Korea, and because that I have use something I already tried – I created list in PeerGuradian and it work good. I know that isn’t so good way, and I spent lots of time in search for a solution – I even think to buy some Cisco network router, but I decide to try this solution because I already have all time running pc and this will be nice solution. Now I want to transfer that PG list into monowall. Normally I will fill up what I need to fill up, but I am not so familiar with those kinds of rules and I need help

Can I get short lead how to set up rule for instance to block this

59.104.0.0 - 59.105.255.255

I want to block whole network – and I have range from start till end of IP address they use. I have several of those network from which I experienced attacks.

This is for the beginning – I will have more questions – surely Smiley

Thanks in advance
Spel
« Reply #1 on: July 26, 2007, 10:33:37 »
SpelingMistakes *
Posts: 4

Nobady ? - Huh -
http://doc.m0n0.ch/handbook/firewall.html
Even here there is nothing about it Sad
« Reply #2 on: July 28, 2007, 22:49:56 »
cmb *****
Posts: 851

http://doc.m0n0.ch/handbook/faq-block-ip-range.html
« Reply #3 on: July 30, 2007, 00:50:49 »
SpelingMistakes *
Posts: 4

How - where to fill that - and how

How to set up that if there isn’t explained nothing - Except using a mask with /number

Look how many fields has have to fill - and there is noting how to fill them

(http://img442.imageshack.us/img442/4493/monowallmz0.th.jpg)
« Reply #4 on: July 30, 2007, 00:56:40 »
cmb *****
Posts: 851

You can choose network for source and destination. The CIDR range (the network + /number) specified determines the IP range.

http://www.subnetmask.info/ is a good tool for figuring out subnet ranges.

Read up on IP subnetting if you don't understand CIDR. This is a good start.
http://en.wikipedia.org/wiki/Classless_Inter-Domain_Routing
« Reply #5 on: July 30, 2007, 03:16:59 »
SpelingMistakes *
Posts: 4

I didn’t mean that - I have tot that there is something which I didn’t know - I try and I already set up some rules.

When i start analysing what i have there and with some tips from frend – i finish job – but now there is fine tuning end similar things

Spel –

Ps Thanks
 
Pages: [1]
 
 
Powered by SMF 1.1.20 | SMF © 2013, Simple Machines