Internet filtering rules -> problem with IP blocking

Discussion in 'LnS English Forum' started by j_o_m_g, Jul 15, 2006.

Thread Status:
Not open for further replies.
  1. j_o_m_g

    j_o_m_g Registered Member

    Joined:
    May 25, 2006
    Posts:
    5
    Hi,
    I've reviewed the LnS logs from past few days and spotted some repeating attacks/ connection attempts from the same IP addresses. Hence, decided to block these IPs and created certain rules. However, these seem not working; the attacks from given IPs are blocked by other rules (as so far), which - to my perspective - shouldn't be the case, since I placed new rules on the top of the Internet filtering ruleset. At first I put the concerned IPs in both directions (as a source and target), but it didn't worked, so changed only into source addresses. Didn't succeed either :-(

    I checked the user manual but this case is unfortunately not described therein.

    I enclose the screenshots of two of the created rules (these are maybe not of best quality - images saved through Paintbrush). For your acknowledgement, "dowolny/-e" means "any" in Polish.


    http://img239.imageshack.us/img239/7184/lnsrule1sr7.jpg
    http://img142.imageshack.us/img142/1289/lnsrule2bw5.jpg

    Please advice me on how to succeed in creating such rules.

    Many thanks in advance.

    Cheers!
     
  2. Climenole

    Climenole Look 'n' Stop Expert

    Joined:
    Jun 3, 2005
    Posts:
    1,640
    Hi j_o_m_g :)

    The best place to block an IP or a range of IPs is in the begining of the rules list. An image is better than 1000 words so I'll give you an example of one of my rules. As you see the Destination address must be tour Ip address: @IP.
     

    Attached Files:

Thread Status:
Not open for further replies.