Blocking certain external clients from port forward

Adam Kropelin <adam-NB+apYvvl4dWk0Htik3J/[email protected]>
Newsgroups gmane.comp.security.ipcop.user
Message-ID <CADAPGLrBUxAeBpHdTVwS6xhPPV6dnStJM4q_RKjDjRVdr09E-Q@mail.gmail.com>
Hello,

First off, I've been a very happy ipcop user for over a decade. Thanks to
all for the hard work on this great tool!

Now for my question:

I'm using ipcop 2.1 and I have a simple port forward rule allowing Red
traffic for a given service from thru to a Green host. This works perfectly.

Recently I have identified several abusive Red hosts and would like to
block those specific hosts from utilizing this port forward.

I added an "External IPCop Access" rule to DROP packets to that service
from the bad Red clients. Nothing seemed to change; I am guessing the port
forward rule has higher priority?

As a workaround I added an outgoing rule to DROP outbound traffic to the
bad hosts which has the effect of not allowing their TCP sessions to be
established.

I also considered adding a rule to the local firewall on the Green host
itself, but from a paranoia standpoint I would prefer that the rogue hosts
not be able to get any packets thru ipcop in the first place.

Any idea how I should address this?

Thanks in advance!
--Adam
------------------------------------------------------------------------------
_______________________________________________
IPCop-user mailing list
[email protected]
Manage your subscription or unsubscribe
https://lists.sourceforge.net/lists/listinfo/ipcop-user
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.