• February 25, 2025, 12:13:31 AM
  • Welcome, Guest
Please login or register.

Login with username, password and session length
Advanced search  

News:

This Forum Beta is ONLY for registered owners of D-Link products in the USA for which we have created boards at this time.

Author Topic: DFL-210: Blocking spoofed Reserved and Local addresses  (Read 5092 times)

Monstah

  • Level 1 Member
  • *
  • Posts: 2
DFL-210: Blocking spoofed Reserved and Local addresses
« on: October 13, 2009, 09:47:39 PM »

Hi,

I'm fairly new to configuring firewalls and we've just got a DFL-210.  I'm looking at compiling my ruleset and something I wanted to ask about was how to block reserved and local address that are inbound on the wan interface.  I want to drop spoofed 192.168.X.X, 172.16.X.X etc from coming in but I can't work out how to make rules that are that detailed.

It's possible I'm approaching this the wrong way so please excuse my ignorance.

Any help would be much appreciated.

Cheers

Dan
Logged

Fatman

  • Level 9 Member
  • ****
  • Posts: 1675
Re: DFL-210: Blocking spoofed Reserved and Local addresses
« Reply #1 on: October 15, 2009, 08:53:24 AM »

The IP Rules listed on this firewall are followed by a default deny that rejects all traffic not specifically listed.

IP Rules could be made specifically to block this traffic, but not only would that be covered by the default deny, but the subject of Access Rules comes up, Access rules define interfaces and Ingress networks, and are evaluated before IP Rules.

You can't see them but by default an Access Rule is created allowing ingress traffic from interface networks on their own interfaces, there is also a default deny Access Rule.

In summary, if you do nothing you are covered, or your could write an IP Rule, Access Rule, or both to specifically block this traffic, and you would be extra covered.  It is your call.
Logged
non progredi est regredi

Monstah

  • Level 1 Member
  • *
  • Posts: 2
Re: DFL-210: Blocking spoofed Reserved and Local addresses
« Reply #2 on: October 17, 2009, 02:46:07 PM »

 :D  Thanks for the reply Fatman.

That makes a lot of sense, Re: implicit deny etc, so I can see that I'm covered without having to worry about configuring specific rules.

Cheers.
Logged

Fatman

  • Level 9 Member
  • ****
  • Posts: 1675
Re: DFL-210: Blocking spoofed Reserved and Local addresses
« Reply #3 on: October 19, 2009, 08:50:53 AM »

I hope this product works out for you, best of luck!
Logged
non progredi est regredi