 muiredisedESSE QUAM VIDERI join:2007-06-11 Tacoma, WA kudos:1 2 edits | Are you talking about blocking local ip addresses on your LAN from accessing the internet or remote ip addresses from accessing your LAN?
If you are talking about blocking someone from sending you messages or accessing services on your computer the 2wire gateway doesn't support this level of fine grained firewall control. You can accomplish this at the machine level however. Gotta love iptables...
iptables -A INPUT -s 11.22.33.44 -j DROP
Oh... you say you aren't using *nix with iptables? Hmmmm... well I haven't been a Windows user for awhile, but maybe this will work...
Click 'Start' > 'Run' >type 'MMC' press ok.
In the console click > 'File' > 'Add/Remove Snap in'
In the 'Standalone Tab' click The 'add' button
Seclect 'IP Security Policy Managment' > 'ADD' > 'Local Computer' > 'finish' > 'close' > 'ok'
You should now be back to the console.
In the left frame right click 'IP security policies on local computer' > 'Create IP security policy'
Click Next and then name your policy 'Block IP' and type a description.
Click 'Next' then leave 'activate' ticked then click 'Next'
leave the 'edit properties ticked and click 'Finish'
You should now have the properties window open.
Click 'ADD' then click 'Next' to continue.
Leave 'This rule does not specify a tunnel' selected and click 'next'
Leave 'all network connections' selected and click 'next'
You should now be on the IP filter list. You need to create a new filter, so dont select any of the default ones. Click 'ADD'
Type a Name for your list, call it 'IP block list'
Type a description in, can be same as name.
Click 'ADD' then click 'Next' to continue.
In the description box type a description. As its the first IP you are blocking call it 'IP1' or 'IP Range 1'
Leave ticked the 'Mirrored. Match packets with the exact opposite source and destination addresses'
Click 'Next'
The 'Source address' should be left as 'My IP address' click 'Next'
You can now select 'A Specific IP address' or 'A Specific Subnet' for the Destination address.
Type in the IP address you want to block and if blocking a subnet type in the subnet block. Click 'next'
Leave the protocol type as 'Any' and click 'Next' and then 'Finish'
If instead you want to keep one particular machine on your LAN from accessing certain services, sites, or web resources then you are going to need some sort of content filtering/access controls... both are available as add-on services for 2wire with some ISPs.
Hope that helps get you started.
-- Assiduus usus uni rei deditus et ingenium et artem saepe vincit |