RRAS packet filtering

  • Thread starter Thread starter shahadat
  • Start date Start date
S

shahadat

Hello,

I have been trying for hours to block traffic for a specific port. I
modified the Input filters on the Public interface but nothing I do
seems to make a difference. I even removed all input filters, then
added a single input filter for FTP on the Public interface and I
selected the "Drop
all packets except those listed", but I can still get in via FTP, HTTP,
or anything else.

My question is how to I get these input filters setup and working? The
system is Windows 2003. I am using the RRAS service for routing. The
system has two NIC cards, one is attached to a DSL line, the other is
attached to the hub of the network. NAT is working
correctly. I have "basic firewall" checked on the public interface.

I couldn't find any help anywhere in the internet on how to use filters
to block specific services like FTP, SMTP, etc. and only allow internet
browsing (HTTP)

Thanks in advance.
 
Hi Shaha,

Just got done with a similar problem... We rebooted the server to
resolve. It seemed after applying various tweaks and test cases, RRAS
got confused.

Our case was, "How Not to be an ISP for Corporate Dialup Users". Users
were running up inordinate phone bills. We blocked all Internet
Services traffic (HTTP, Secure HTTP, SMTP, FTP, and Citrix).

If you need details, I can send you a word document on the
documentation I just finished. Lots of screen shots ;). It covers just
about everything including Routing setup, DHCP setup, RA Policies,
Filter setup, User Profile Settings, etc.

It appears or case is a bit different - we were dealing with a
digiboard full of modems.

My short answer on blocking traffic is select 'Permit all Except...'.
When creating the filters:

* Create the same filers for both Input and Output.
* Leave Source Address and Source Network unchecked (this matches
'User's Address')
* Leave Destination Address and Destination Network Mask unchecked
(this matches 'Any')
* Specify Protocol
* Leave Source Port blank (this matches 'Any')
* Specify Destination Port

In our case, we were able to remove the Output Filters after we
verified both gave us the behavior we desired.

Jeff
 
Hi Jeff,

Thanks a lot for you reply. I am going to try it first thing monday
morning. Please can you email the doc you have created. I think it will
be immensely helpful.

Thank you so much.
Shahadat
 
Back
Top