Blocking certain external clients from port forward
Adam Kropelin <adam-NB+apYvvl4dWk0Htik3J/[email protected]>
| Newsgroups | gmane.comp.security.ipcop.user |
|---|---|
| Message-ID | <CADAPGLrBUxAeBpHdTVwS6xhPPV6dnStJM4q_RKjDjRVdr09E-Q@mail.gmail.com> |
Hello, First off, I've been a very happy ipcop user for over a decade. Thanks to all for the hard work on this great tool! Now for my question: I'm using ipcop 2.1 and I have a simple port forward rule allowing Red traffic for a given service from thru to a Green host. This works perfectly. Recently I have identified several abusive Red hosts and would like to block those specific hosts from utilizing this port forward. I added an "External IPCop Access" rule to DROP packets to that service from the bad Red clients. Nothing seemed to change; I am guessing the port forward rule has higher priority? As a workaround I added an outgoing rule to DROP outbound traffic to the bad hosts which has the effect of not allowing their TCP sessions to be established. I also considered adding a rule to the local firewall on the Green host itself, but from a paranoia standpoint I would prefer that the rogue hosts not be able to get any packets thru ipcop in the first place. Any idea how I should address this? Thanks in advance! --Adam ------------------------------------------------------------------------------ _______________________________________________ IPCop-user mailing list [email protected] Manage your subscription or unsubscribe https://lists.sourceforge.net/lists/listinfo/ipcop-user