Blocking inbound connections

Comments

9 comments

  • Avatar
    James Berry

    I can now see how to add allow rules - but what about deny ones? (Eg block china)

    0
    Comment actions Permalink
  • Avatar
    Firewalla

    You can just add a block "region" rule to all of your devices. See https://help.firewalla.com/hc/en-us/articles/360035080933-Firewalla-Regional-Filtering-Geo-IP-TLD-Blocking

    0
    Comment actions Permalink
  • Avatar
    James Berry

    This sounded like an outbound rule? The directionality and application of firewalla rules hurt my head, they are all over the place!

    0
    Comment actions Permalink
  • Avatar
    Firewalla

    Unless specified, all rules are in both directions. 

    1
    Comment actions Permalink
  • Avatar
    James Willhoite

    Old thread, but I have a use case for this too. We have been getting botnet attacks to some of our public facing servers. I’ve got a long list of IP addresses to block, but only want to block incoming only. This botnet attacking is happening to servers NOT on the firewalla yet. But I’ve created a target list with these IP subnets. I would like to block Incoming only. I already have a “Allow Sources” for the USA only on the Port Forward, but wish I could also have a Block too. Some of these subnets are from the US.

    0
    Comment actions Permalink
  • Avatar
    Firewalla

    This means you want LAN traffic going to the "long list of bad IP"? 

    We are trying to avoid this separation; it will make debugging problems much more difficult. 

    0
    Comment actions Permalink
  • Avatar
    James Willhoite

    No, Incoming from Public. You have the ability to say allow from target list, ip address, region .... while this is great, would like to also have the ability to say block from this target list. One of the subnets I have blocked is 85.0.0.0/8 which is a wide net, but in the event there is a valid IP address a device needs to reach OUT to, I don't want to block it.

    0
    Comment actions Permalink
  • Avatar
    Firewalla

    If you don't want to block it, you can just use the allow rule. You don't need to have directions

    0
    Comment actions Permalink

Please sign in to leave a comment.