Blocking Sites
User Guide
185
•
Permanently blocked sites–which are listed in the
configuration file and change only if you manually
change them.
•
Auto-blocked sites–which are sites the Firebox adds
or deletes dynamically based on default packet
handling rules and service-by-service rules for denied
packets. For example, you can configure the Firebox to
block sites that attempt to connect to forbidden ports.
Sites are temporarily blocked until the auto-blocking
mechanism times out.
For information on auto-blocking sites using the
protocol anomaly detection (PAD) feature, see
“Configuring the Incoming SMTP Proxy” on page 138.
Firebox System auto-blocking and logging mechanisms
can help you decide which sites to block. For example,
when you find a site that spoofs your network, you can
add the offending site’s IP address to the list of perma-
nently blocked sites.
Note that site blocking can be imposed only to traffic on
the Firebox’s external interface. Connections between the
trusted and optional interfaces are not subject to the
Blocked Sites feature.
Blocking a site permanently
You may know of hosts on the Internet that pose constant
dangers, such as a university computer that has been used
more than once by student hackers who try to invade your
network.
Use Policy Manager to block a site permanently. The
default configuration blocks three network addresses–
10.0.0.0/8, 172.16.0.0/12, and 192.168.0.0/16. These are the
private (“unconnected”) network addresses. Because they
are for private use, backbone routers should never pass
traffic with these addresses in the source or destination
field of an IP packet. Traffic from one of these addresses is
almost certainly a spoofed or otherwise suspect address.
RFCs 1918, 1627, and 1597 cover the use of these addresses.
Summary of Contents for Firebox X10E
Page 1: ...WatchGuard Firebox System User Guide WatchGuard Firebox System ...
Page 12: ...xii WatchGuard Firebox System ...
Page 44: ...Chapter 2 Service and Support 22 WatchGuard Firebox System ...
Page 61: ...Cabling the Firebox User Guide 39 ...
Page 68: ...Chapter 3 Getting Started 46 WatchGuard Firebox System ...
Page 78: ...Chapter 4 Firebox Basics 56 WatchGuard Firebox System ...
Page 156: ...Chapter 8 Configuring Filtered Services 134 WatchGuard Firebox System ...
Page 182: ...Chapter 9 Configuring Proxied Services 160 WatchGuard Firebox System ...
Page 220: ...Chapter 11 Intrusion Detection and Prevention 198 WatchGuard Firebox System ...
Page 242: ...Chapter 12 Setting Up Logging and Notification 220 WatchGuard Firebox System ...
Page 256: ...Chapter 13 Reviewing and Working with Log Files 234 WatchGuard Firebox System ...
Page 274: ...Chapter 14 Generating Reports of Network Activity 252 WatchGuard Firebox System ...