Stopping Open DNS - FireBrick 105: Difference between revisions
No edit summary |
(→FireBrick 105: clean up) |
||
(11 intermediate revisions by one other user not shown) | |||
Line 1: | Line 1: | ||
[[File: |
[[File:105-small.gif]] |
||
=FireBrick 105 |
=FireBrick 105= |
||
⚫ | |||
[[File:FireBrick-icons.png]] |
|||
⚫ | |||
''' |
|||
However, in some cases, customers disable the firewall by adding a rule that allows all traffic in. In this case, a new rule is needed to block DNS to the FireBrick. |
However, in some cases, customers disable the firewall by adding a rule that allows all traffic in. In this case, a new rule is needed to block DNS to the FireBrick. |
||
==Instructions== |
|||
Create a Firewall filter to block port 53, from the WAN to the FireBrick, and make sure it's before any other rule that may allow this traffic in: |
Create a Firewall filter to block port 53, from the WAN to the FireBrick, and make sure it's before any other rule that may allow this traffic in: |
||
Name: BlockOpenDNS |
Name: BlockOpenDNS |
||
Line 15: | Line 19: | ||
Target ports: 53 |
Target ports: 53 |
||
Protocol: UDP |
Protocol: UDP |
||
*Then re-test from the Control Pages: https://clueless.aa.net.uk/dnsresolvers.cgi |
|||
[[File:FireBrick-OpenDNS-Rule.png]] |
[[File:FireBrick-OpenDNS-Rule.png]] |
||
[[Category:FireBrick]] |
|||
[[Category:Open DNS Resolvers]] |
|||
[[Category:AA Routers]] |
Latest revision as of 23:58, 17 August 2018
FireBrick 105
In a factory state the Filters on a FireBrick 105 will not allow DNS to the FireBrick from the WAN - the default state is to block incoming traffic, but to allow outgoing traffic. However, in some cases, customers disable the firewall by adding a rule that allows all traffic in. In this case, a new rule is needed to block DNS to the FireBrick.
Instructions
Create a Firewall filter to block port 53, from the WAN to the FireBrick, and make sure it's before any other rule that may allow this traffic in:
Name: BlockOpenDNS Source: WAN Target: FireBrick (The name of your FireBrick) Action: Drop Target ports: 53 Protocol: UDP
- Then re-test from the Control Pages: https://clueless.aa.net.uk/dnsresolvers.cgi