republican-creole
Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » US Telco Support » Verizon » Verizon Fiber Optics » [northeast] How to block outbound traffic...
Search Topic:
Uniqs:
198
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Post a:
Post a:
DIAMOND BAR, CA. FIOS Updates? »
« Why the replacement Power Adapter?  
AuthorAll Replies

batsona
Maryland

join:2004-04-17
Ellicott City, MD
·Verizon FIOS
·Vonage

 [northeast] How to block outbound traffic...

Click for full size
**rant-on**
OK, I want to throw the actiontec into the driveway and run over it. I need money for a good Cisco ASA, or a Juniper SSG5... At least I'd know how to run those
**rant-off*

Ok, that's out of my system. Now, I need to block access to a certain website that my daughter's spending too much time on. I've tried creating rules in every one of the 'sections' for the outbound traffic on the actiontec, but I can still browse to the sites with the greatest of ease. (see attachment). Can someone show me what I'm doing wrong? I'm using the syntax of an existing inbound rule that does work. There's got to be a fundimental that I'm not getting here. (Just like the implicit-accept at the end of the rules, instead of the implicit-deny)

I already know I've got the right IPs for the website...


redmond

join:2001-04-24
Wayne, PA
I use opendns to do that.....


jefe
Premium
join:2001-05-19
Northport, NY
reply to batsona
Have you tried the Parental Control feature? It seems like that will do exactly what you're trying to do.


birdfeedr
Premium,MVM
join:2001-08-11
Warwick, RI
·Verizon FIOS

reply to batsona
Click for full size
Advanced Filter Rule
Your attachment does not have a rule, therefore not blocking anything. Attached screenshot shows a rule that blocks access to dslreports.com, until it is disabled.

I created it by going to Firewall Settings, Advanced Filtering, Add to Broadband Connection (Ethernet) Rules, Source Address Any, Destination Specify, Add Network Object, Specify Hostname: dslreports.com, Apply, Protocol Any, Drop, Always, Apply, Apply. You know you got it right when you get back to the nag screen to enter Firewall Settings.

If you can handle a Cisco, you can follow these keywords. Unless you want a step-by-step with screenshots.

Not sure if Parental Controls does the same thing. The more you add to the rule, the more complex (and performance draining). It's possible to add a schedule.

And I don't even remember why I set Rule #0.

In this process, the hostname specification ends up resolving to an IP address. You'll have more problems if the destination you're blocking is dynamic.

batsona
Maryland

join:2004-04-17
Ellicott City, MD
·Verizon FIOS
·Vonage

Click for full size
OK - fixed it. However, I'm convinced that the people who develop firmware for the Actiontec have never seen, nor played with a router, nor are they familiar with basic concepts...

I put my rule in the Ethernet Section of the "Input" rule. The explaination says, this is where you block traffic inbound from the Internet... This is apparently not true. The "input" section means traffic inbound on ANY interface (including the internal ethernet)

If you pay attention to the little explinations, you'll never get it right: "inbound" (from the Internet) means inbound on ANY interface, and "Outbound" (to internet) means outbound on ANY interface. Anyway, attached is my rulebase. Maybe this is a problem in revision E?


birdfeedr
Premium,MVM
join:2001-08-11
Warwick, RI
·Verizon FIOS


1 edit
said by batsona See Profile :

I put my rule in the Ethernet Section of the "Input" rule. The explaination says, this is where you block traffic inbound from the Internet... This is apparently not true. The "input" section means traffic inbound on ANY interface (including the internal ethernet)

If you pay attention to the little explinations, you'll never get it right: "inbound" (from the Internet) means inbound on ANY interface, and "Outbound" (to internet) means outbound on ANY interface. Anyway, attached is my rulebase. Maybe this is a problem in revision E?
Inbound filter seems applicable to ban unsolicited traffic from a particular address. Say you have a server listening and wanted to ban a particular address. That's inbound. However, traffic coming in as a result of something originated going out may have a higher/different priority so the inbound filter doesn't apply.

Outbound filter definitely works. When I banned traffic out to dslreports, nothing got out that dslreports could reply to. The hourglass was spinning forever, at least until I disabled the rule.

If you're trying to stop website access, apply an outbound filter.

[edit to add] Looking at your Ethernet filter rules, looks like you want to block access to Disney, among others. You can create the same rules in outbound WAN PPPoE, for all, some, or one PC on the LAN. Outbound is where I'd put them.

You're not the first to say Actiontec GUI is counterintuitive.

batsona
Maryland

join:2004-04-17
Ellicott City, MD
·Verizon FIOS
·Vonage

You're correct: [outbound] PPP, or [inbound] ethernet were the two places where my rule actually worked. The way logic works [at least on Cisco devices], you always block traffic *inbound* thru an interface, not outbound thru it. That's why it seems counterintuitive...

Anyway, now that I see how this works, we can call this solved, but I'm still gritting my teeth


jefe
Premium
join:2001-05-19
Northport, NY
I still think Parental Controls would've done what you needed, and without and greeting of teeth.


birdfeedr
Premium,MVM
join:2001-08-11
Warwick, RI
·Verizon FIOS

Parental Control is the only feature that says there may be a slight performance hit when you create the rule. It's more complex because of a schedule, and keyword filtering.

A simpler addressed-based filter, once working, may be worth the aggravation of gritted teeth.
-
Forums » US Telco Support » Verizon » Verizon Fiber OpticsDIAMOND BAR, CA. FIOS Updates? »
« Why the replacement Power Adapter?  


Thursday, 10-Dec 02:07:44 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.
page compression OFF
Most commented news this week
· [200] Sprint Sued For Distracted Driving Death
· [116] AT&T Launching New 24 Mbps U-Verse Tier
· [82] 3G Network Test Says AT&T Is Tops
· [72] Mediacom Unveils 105 Mbps Pricing
· [66] Sprint Poised For A Turnaround?
· [66] WPA Cracker: Test WPA-PSK Networks In 20 Minutes
· [66] AT&T Hints At Usage-Based iPhone Data Pricing
· [51] The Future Of Wi-Fi Is Bright
· [47] Site Leaks Yahoo, Verizon Fed Data Share Pricing
· [45] Microwaving Your Innards Is Not 'Extreme'
Most people now reading
· Windows 7 boot manager editing questions [Microsoft Help]
· Cross Server Dungeon Experience [World of Warcraft]
· The aftermath [World of Warcraft]
· ICC strats [World of Warcraft]
· [ Classes] Druid tanking: rotation and glyphs [World of Warcraft]
· Official "Invite" thread Part 3 - ALL INVITES GO HERE ! [Filesharing Software]
· SB6120 Firmware update [Comcast HSI]
· Adobe Flash Player version 10.0.42.34 [Security]
· Lawyers Claim Palin Hack Suspect's PC Had Spyware [Security]
· ICC Strats??? [World of Warcraft]