Quantcast
Channel: EdgeRouter topics
Viewing all articles
Browse latest Browse all 20028

trying to block a set of ip addresses

$
0
0

I am trying to block all my cameras from going to the internet. Using an ER-X

here is my firewall config:

 

firewall {
all-ping enable
broadcast-ping disable
group {
address-group cameras {
address 192.168.1.20
address 192.168.1.21
address 192.168.1.22
address 192.168.1.23
address 192.168.1.24
address 192.168.1.25
address 192.168.1.26
address 192.168.1.27
address 192.168.1.28
address 192.168.1.29
description cameras
}
}
ipv6-receive-redirects disable
ipv6-src-route disable
ip-src-route disable
log-martians enable
name WAN_IN {
default-action drop
description "WAN to internal"
rule 1 {
action drop
description block_Cameras
destination {
address !192.168.1.0/24
}
log disable
protocol all
source {
group {
address-group cameras
}
}
state {
established enable
invalid disable
new enable
related enable
}
}
rule 2 {
action accept
description "allow established/related"
log disable
state {
established enable
related enable
}
}
rule 3 {
action drop
description "Drop invalid state"
log enable
state {
invalid enable
}
}
}
name WAN_LOCAL {
default-action drop
description "WAN to router"
enable-default-log
rule 1 {
action accept
description "Allow established/related"
state {
established enable
related enable
}
}
rule 2 {
action accept
description "allow incoming pptp"
destination {
port 1723
}
log disable
protocol tcp
}
rule 3 {
action accept
description "allow incoming pptp gre"
log disable
protocol gre
}
rule 4 {
action accept
description "allow l2tp"
destination {
port 500,1701,4500
}
log disable
protocol udp
}
rule 5 {
action accept
description "allow esp"
log disable
protocol 50
}
rule 6 {
action drop
description "Drop invalid state"
log enable
state {
invalid enable
}
}
}
options {
mss-clamp {
interface-type pptp
mss 1412
}
}
receive-redirects disable
send-redirects enable
source-validation disable
syn-cookies enable
}
 
 
Have tried putting the block statement as the 3rd rull but no difference.
 
 

Viewing all articles
Browse latest Browse all 20028

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>