PC Review


Reply
Thread Tools Rate Thread

Advanced firewall rules help please.

 
 
Martin Connolly
Guest
Posts: n/a
 
      4th Jul 2009
I'm trying to create a rull, that will lock-down a Vista Home Premium PC, so
that it can only gain access to the internet via a corporate proxy on a
Cisco VPN client. I can block all port 80 and 443 traffic, but then can't
get a rule to work that permits traffic to the VPN gateway or proxy server.
I guess the port 80 block is getting a higher priority to the gateway permit
or something similar.

Any ideas please?

I need this to replace Novell Endpoint Security suite, which simply doesn't
work on Vista, even though they claim it does!


Thanks,

Martin.

 
Reply With Quote
 
 
 
 
Martin Connolly
Guest
Posts: n/a
 
      5th Jul 2009
A block rule always takes priority over an allow rule. Once ports 80 and 443
are blocked, another rule exception will never un-block them.

Instead you have to make the same block rule not apply to the proxy server,
so that it will be exempt.

Create an Outgoing rule to block remote ports TCP 80 and 443 , and in the
scope set two ranges for the remote IP address that exclude the proxy
server. Ignore the VPN tunnel IP addresses, as the firewall will not see
those.

So, for example, if your proxy server on the other side of the tunnel has an
IP address of 172.10.45.100, then the scope should 0.0.0.0 - 172.10.45.99
and 172.10.45.101 - 255.255.255.255.

Simple!

Martin

 
Reply With Quote
Reply

Thread Tools
Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Windows Firewall and WF with Advanced Security rules not working ruisu Windows Vista Security 5 7th Feb 2009 05:00 AM
More Advanced Rules =?Utf-8?B?TWljaGFlbA==?= Microsoft Outlook Discussion 1 25th Sep 2007 01:49 PM
advanced rules =?Utf-8?B?TWlrZUY=?= Microsoft Outlook Installation 1 3rd Dec 2006 09:20 PM
Firewall rules: how to get list of allow program through firewall? =?Utf-8?B?TWFub2ogQ2hhbmNoYXdhdCwgU3ltYW50ZWMgQ29y Windows Vista Security 1 18th Oct 2006 08:55 PM
XP Pro firewall Advanced tab does not appear Jim Windows XP Networking 2 20th Oct 2003 08:23 PM


Features
 

Advertising
 

Newsgroups
 


All times are GMT +1. The time now is 05:42 AM.