PDA

View Full Version : How to add a Kerio Rule to Block an IP Range?


WinHelp2002
February 12th, 2006, 04:12 AM
How to add a Rule to Block a specific IP Range? ... (Kerio v.4.2.3)
[Example]
Netrange: 81.9.5.0 - 81.9.5.255 (81.9.5.0/32)

And would this method be the same as blocking one IP Address?
[Example]
85.255.113.173

CrazyM
February 12th, 2006, 04:36 AM
-{ Quote: "How to add a Rule to Block a specific IP Range? ... (Kerio v.4.2.3)
[Example]
Netrange: 81.9.5.0 - 81.9.5.255 (81.9.5.0/32)" }-
While I have not used the latest version of Kerio, the advanced rules should allow you to manually create such a rule. Is this for outbound, inbound or both?

-{ Quote: "And would this method be the same as blocking one IP Address?
[Example]
85.255.113.173" }-
Creating the rule would be similar, whether single IP is specified or a range.

Regards,

CrazyM

WinHelp2002
February 13th, 2006, 10:11 AM
CrazyM,
-{ Quote: "Is this for outbound, inbound or both?" }- For both ...
Well ... I was hoping someone with v. 4.2 would know "How To" ...

Kerodo
February 13th, 2006, 11:21 AM
I am not running Kerio now so I can't check, but I believe in the Network section/tab there is a Packet Filter button. Click that, and in there you can set up all your custom rules. If you want to set up rules for DNS/DHCP/ICMP etc then also make sure you disable the Predefined Rules.

CrazyM
February 14th, 2006, 12:40 AM
-{ Quote: "For both ..." }-
Your firewall should already be blocking unsolicited inbounds. Unless you want to log or not log these specifically you should not need an inbound rule.
-{ Quote: "Well ... I was hoping someone with v. 4.2 would know "How To" ..." }-
As Kerodo eluded to, the advanced packet filtering should allow you to create a rule manually. The wizard should be fairly intuitive.

Action: Block
Direction: Outbound
Application: Any
Protocol: Any
Local Port: Any
Remote Address: range 81.9.5.0 - 81.9.5.255
Remote Port: Any
Logging: Enabled

Regards,

CrazyM

WinHelp2002
February 14th, 2006, 01:00 AM
CrazyM,
Ok thanks ... I'll give that a try