11.07.2015 Views

WatchGuard Firebox System 7.0 User Guide

WatchGuard Firebox System 7.0 User Guide

WatchGuard Firebox System 7.0 User Guide

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Blocking Sites• Permanently blocked sites–which are listed in theconfiguration file and change only if you manuallychange them.• Auto-blocked sites–which are sites the <strong>Firebox</strong> addsor deletes dynamically based on default packethandling rules and service-by-service rules for deniedpackets. For example, you can configure the <strong>Firebox</strong> toblock sites that attempt to connect to forbidden ports.Sites are temporarily blocked until the auto-blockingmechanism times out.For information on auto-blocking sites using theprotocol anomaly detection (PAD) feature, see“Configuring the Incoming SMTP Proxy” on page 138.<strong>Firebox</strong> <strong>System</strong> auto-blocking and logging mechanismscan help you decide which sites to block. For example,when you find a site that spoofs your network, you canadd the offending site’s IP address to the list of permanentlyblocked sites.Note that site blocking can be imposed only to traffic onthe <strong>Firebox</strong>’s external interface. Connections between thetrusted and optional interfaces are not subject to theBlocked Sites feature.Blocking a site permanentlyYou may know of hosts on the Internet that pose constantdangers, such as a university computer that has been usedmore than once by student hackers who try to invade yournetwork.Use Policy Manager to block a site permanently. Thedefault configuration blocks three network addresses–10.0.0.0/8, 172.16.0.0/12, and 192.168.0.0/16. These are theprivate (“unconnected”) network addresses. Because theyare for private use, backbone routers should never passtraffic with these addresses in the source or destinationfield of an IP packet. Traffic from one of these addresses isalmost certainly a spoofed or otherwise suspect address.RFCs 1918, 1627, and 1597 cover the use of these addresses.<strong>User</strong> <strong>Guide</strong> 185

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!