This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Block list of ip address for a web proxy.

At the moment I cannot change my Astaro config too much. I am trying to block vtunnel.com. I did a nslookup on her, and got a list of 27 ip addresses.

> nslookup vtunnel.com
Server:  vtunnel.com
Addresses:  67.159.2.154
          67.159.3.226
          67.159.9.42
          67.159.23.76
          67.159.33.211
          67.159.46.194
          67.159.47.140
          67.159.47.204
          67.159.47.205
          67.159.47.206
          67.159.50.133
          67.159.51.156
          67.159.51.157
          67.159.51.158
          67.159.56.236
          74.63.75.228
          74.63.75.229
          74.63.75.230
          74.63.82.148
          74.63.82.156
          74.63.86.164
          74.63.86.172
          74.63.89.202
          74.63.89.203
          74.63.89.210
          74.63.89.211
          74.63.107.22


Is there anyway to add these address as on rule in the packet filter? Is the only way to block them by creating a rule for each ip address? Thanks for any input with my issue.

John


This thread was automatically locked due to age.
  • Unfortunately, John, I'm fairly certain the traffic isn't subject to the packet filter rules since it's captured by the proxy before the rules are considered.  You have to block the traffic in the proxy if you use the proxy.

    I just blocked vtunnel.com in Astaro V7.401, and that worked.  When I try to access the numeric IPs, I get the following, regardless of whether vtunnel.com is blocked:
    ERROR
    The requested URL could not be retrieved

    --------------------------------------------------------------------------------

    While trying to retrieve the URL: http://67.159.23.76/ 

    The following error was encountered: 

    Zero Sized Reply 
    Squid did not receive any data for this request. 


    Cheers - Bob
     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
    • Unfortunately, John, I'm fairly certain the traffic isn't subject to the packet filter rules since it's captured by the proxy before the rules are considered.  You have to block the traffic in the proxy if you use the proxy.

      I just blocked vtunnel.com in Astaro V7.401, and that worked.  When I try to access the numeric IPs, I get the following, regardless of whether vtunnel.com is blocked:


      Cheers - Bob

      Thanks for replaying Bob. I was actually created a thread about vtunnel in the Content Filter forum here. I didn't want to have to enable Scan HTTPS (SSL) Traffic because we do not have a public/private wireless network congifured here yet. I was hoping that I could just have traffic going to that domain just get blockholed, so I could "disable" this one proxy the kids in my school district have learned how to access. I think my solution right now is just to enable Scan HTTPS (SSL) Traffic, and when someone out of the district comes in and needs internet access I'll just load the SSL cert and give them the wpa key.