EFW Support

Support => EFW SMTP, HTTP, SIP, FTP Proxy Support => Topic started by: alex_t on Tuesday 03 May 2011, 02:13:06 am



Title: PROXY is available from RED
Post by: alex_t on Tuesday 03 May 2011, 02:13:06 am
Hi
I have a problem. I'v noteced that proxy is available from RED interface, inspite of all restrictions on firewall.
Even if  I deny system access to port 8080 (proxy port), i see string
INPUTFW:ALLOW:2:l3    eth1    KEY_TCP     70.37.165.109    56118    ff:ff:14:00:03:00     193.85.. 8080
where 193.85.. is my red interface.
It's a big security breach. Does anybody have suggestions?


Title: Re: PROXY is available from RED
Post by: alex_t on Saturday 07 May 2011, 02:32:57 am
and silence  ???  :(


Title: Re: PROXY is available from RED
Post by: bkarankar on Friday 13 May 2011, 10:00:21 pm
not sure,

but you can try this

create new access rules,
zone "any"
destination "give ur internet network IP"

deny this.

then u need to modify firewall rule
disable all access with firewall (if not required to bypass proxy) and only allow dns and ping/icmp
now, create another rule in firewall to block all incoming request on 8080, 3128 and 8080

let me know if you find any issue


Title: Re: PROXY is available from RED
Post by: Alishba on Monday 16 May 2011, 08:07:31 pm
Dashquid (http://dashquid.com)
fatlossprofessional.co.uk (http://fatlossprofessional.co.uk)
fatlossprofessional (http://fatlossprofessional.co.uk/how-to-lose-weight-fast/)
mobilehelper (http://mobilehelper.co.uk)
securetrip (http://securetrip.co.uk)
whichpetcover (http://whichpetcover.com)
google (http://google.com)
abc (http://abc.com)
facebook (http://facebook.com)
craigslist (http://craigslist.com)


Title: Re: PROXY is available from RED
Post by: alex_t on Monday 13 June 2011, 11:46:12 pm
2 bkarankar:
which firewall do you mean? outgoing traffic?
I've tried, but - same result, so proxy is available from RED.
But I've noticed, when I switch proxy on, system makes system rule in system access section GREEN->RED:8080 Allow.