Blocking outgoing request based on user + IP/host restriction

[email protected]
Newsgroups gmane.comp.security.firewalls.firehol.user
Message-ID <[email protected]>
Hi -

I've had a lot of success blocking all outgoing client requests from the 
apache user (www-data) using firehol. I have the following line in my 
firehol conf:

client all accept user not www-data

This blocks all outgoing requests from things like PHP code etc.

Whilst I like this setup, its a little too restrictive and I'd like to 
open it up to allow access to a few api hosts (paypal for instance). I 
thought just adding the following line above the www-data restriction 
would do this:

client all accept dst "www.paypal.com DNSIP1 DNSIP2"
client all accept user not www-data

So I was expecting this to allow all requests to my DNS hosts and paypal 
(even if they are from the www-data user), but block all other requests 
from the www-data user. It doesnt appear to do this though.

Is there an easy way to do what I want?

Thanks

Marcus



------------------------------------------------------------------------------
The Palm PDK Hot Apps Program offers developers who use the
Plug-In Development Kit to bring their C/C++ apps to Palm for a share 
of $1 Million in cash or HP Products. Visit us here for more details:
http://ad.doubleclick.net/clk;226879339;13503038;l?
http://clk.atdmt.com/CRS/go/247765532/direct/01/
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.