<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: security related block perticular site in Operating System - Linux</title>
    <link>https://community.hpe.com/t5/operating-system-linux/security-related-block-perticular-site/m-p/5047773#M48538</link>
    <description>iptables -A OUTPUT -s YOURLAN -d TARGET_IP_ADDRESS -j DENY&lt;BR /&gt;&lt;BR /&gt;replacing YOURLAN by something like: 192.168.0.0/24 and TARGET_IP_ADDRESS to another CIDR, or an ip address, like: 1.1.1.1&lt;BR /&gt;&lt;BR /&gt;That would block outgoing traffic to that site.&lt;BR /&gt;&lt;BR /&gt;Regards,&lt;BR /&gt;Leandro Daniel Costa</description>
    <pubDate>Fri, 18 May 2007 10:04:23 GMT</pubDate>
    <dc:creator>Leandro Daniel Costa</dc:creator>
    <dc:date>2007-05-18T10:04:23Z</dc:date>
    <item>
      <title>security related block perticular site</title>
      <link>https://community.hpe.com/t5/operating-system-linux/security-related-block-perticular-site/m-p/5047769#M48534</link>
      <description>Hi all,&lt;BR /&gt;&lt;BR /&gt;I am using firestarter in my LAN environment and i want to block a particular website in my LAN environment.&lt;BR /&gt;&lt;BR /&gt;is it possible to block IP address? &lt;BR /&gt;&lt;BR /&gt;How can i block this.&lt;BR /&gt;&lt;BR /&gt;Thanks in Advance.&lt;BR /&gt;&lt;BR /&gt;MKS</description>
      <pubDate>Fri, 18 May 2007 08:51:25 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/security-related-block-perticular-site/m-p/5047769#M48534</guid>
      <dc:creator>monu_1</dc:creator>
      <dc:date>2007-05-18T08:51:25Z</dc:date>
    </item>
    <item>
      <title>Re: security related block perticular site</title>
      <link>https://community.hpe.com/t5/operating-system-linux/security-related-block-perticular-site/m-p/5047770#M48535</link>
      <description>Take a look at this page&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://www.fs-security.com/docs/policy-page.php" target="_blank"&gt;http://www.fs-security.com/docs/policy-page.php&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Here, it explains how to accomplish what you're trying to do.&lt;BR /&gt;You need to block outgoing traffic to that IP address.&lt;BR /&gt;&lt;BR /&gt;Hope it helps&lt;BR /&gt;&lt;BR /&gt;Regards,&lt;BR /&gt;Leandro Costa</description>
      <pubDate>Fri, 18 May 2007 09:32:01 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/security-related-block-perticular-site/m-p/5047770#M48535</guid>
      <dc:creator>Leandro Daniel Costa</dc:creator>
      <dc:date>2007-05-18T09:32:01Z</dc:date>
    </item>
    <item>
      <title>Re: security related block perticular site</title>
      <link>https://community.hpe.com/t5/operating-system-linux/security-related-block-perticular-site/m-p/5047771#M48536</link>
      <description>Yes it's possible. You can do it via firewall or proxy. It depends of how your network connects to Internet.&lt;BR /&gt;&lt;BR /&gt;If you have a Linux gateway with NAT, you should use iptables to block access.&lt;BR /&gt;&lt;BR /&gt;If you use a proxy server like squid, you need to configure access lists and rules.</description>
      <pubDate>Fri, 18 May 2007 09:38:12 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/security-related-block-perticular-site/m-p/5047771#M48536</guid>
      <dc:creator>Ivan Ferreira</dc:creator>
      <dc:date>2007-05-18T09:38:12Z</dc:date>
    </item>
    <item>
      <title>Re: security related block perticular site</title>
      <link>https://community.hpe.com/t5/operating-system-linux/security-related-block-perticular-site/m-p/5047772#M48537</link>
      <description>Thanks Ivan!&lt;BR /&gt;&lt;BR /&gt;I am using linux gateway with NAT.&lt;BR /&gt;Please suggest which command i should append in IPTABLE entry to block a particular web sit that no one can access that site in my LAN env users.&lt;BR /&gt;&lt;BR /&gt;Thanks a lot again&lt;BR /&gt;&lt;BR /&gt;MKS</description>
      <pubDate>Fri, 18 May 2007 09:42:47 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/security-related-block-perticular-site/m-p/5047772#M48537</guid>
      <dc:creator>monu_1</dc:creator>
      <dc:date>2007-05-18T09:42:47Z</dc:date>
    </item>
    <item>
      <title>Re: security related block perticular site</title>
      <link>https://community.hpe.com/t5/operating-system-linux/security-related-block-perticular-site/m-p/5047773#M48538</link>
      <description>iptables -A OUTPUT -s YOURLAN -d TARGET_IP_ADDRESS -j DENY&lt;BR /&gt;&lt;BR /&gt;replacing YOURLAN by something like: 192.168.0.0/24 and TARGET_IP_ADDRESS to another CIDR, or an ip address, like: 1.1.1.1&lt;BR /&gt;&lt;BR /&gt;That would block outgoing traffic to that site.&lt;BR /&gt;&lt;BR /&gt;Regards,&lt;BR /&gt;Leandro Daniel Costa</description>
      <pubDate>Fri, 18 May 2007 10:04:23 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/security-related-block-perticular-site/m-p/5047773#M48538</guid>
      <dc:creator>Leandro Daniel Costa</dc:creator>
      <dc:date>2007-05-18T10:04:23Z</dc:date>
    </item>
    <item>
      <title>Re: security related block perticular site</title>
      <link>https://community.hpe.com/t5/operating-system-linux/security-related-block-perticular-site/m-p/5047774#M48539</link>
      <description>The rule could be like this:&lt;BR /&gt;&lt;BR /&gt;LANIP="192.168.0.1/24"&lt;BR /&gt;DESTHOST=w.x.y.z&lt;BR /&gt;&lt;BR /&gt;iptables -I FORWARD 1 -s $LANIP -d $DESTHOST -j REJECT</description>
      <pubDate>Fri, 18 May 2007 10:04:41 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/security-related-block-perticular-site/m-p/5047774#M48539</guid>
      <dc:creator>Ivan Ferreira</dc:creator>
      <dc:date>2007-05-18T10:04:41Z</dc:date>
    </item>
    <item>
      <title>Re: security related block perticular site</title>
      <link>https://community.hpe.com/t5/operating-system-linux/security-related-block-perticular-site/m-p/5047775#M48540</link>
      <description>Hi Costa!&lt;BR /&gt;&lt;BR /&gt;Accoring to yr command i have put entry in iptables but with REJECT.&lt;BR /&gt;&lt;BR /&gt;But this entry also reject my ping request to other sites also.&lt;BR /&gt;&lt;BR /&gt;means icmp request reject&lt;BR /&gt;&lt;BR /&gt;where is the prob&lt;BR /&gt;plz suggest&lt;BR /&gt;&lt;BR /&gt;MKS</description>
      <pubDate>Fri, 18 May 2007 11:11:04 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/security-related-block-perticular-site/m-p/5047775#M48540</guid>
      <dc:creator>monu_1</dc:creator>
      <dc:date>2007-05-18T11:11:04Z</dc:date>
    </item>
    <item>
      <title>Re: security related block perticular site</title>
      <link>https://community.hpe.com/t5/operating-system-linux/security-related-block-perticular-site/m-p/5047776#M48541</link>
      <description>Hi Ivan!&lt;BR /&gt;&lt;BR /&gt;According to yr given rule, i read somewhere that -s and -d option shoule have same parameter&lt;BR /&gt;&lt;BR /&gt;like -s $192.168.1.0/24&lt;BR /&gt;      -d $x.y.z.w/24&lt;BR /&gt;what should i do.I have to block site (x.y.z.w) for my LAN clients.&lt;BR /&gt;&lt;BR /&gt;According to yr given command&lt;BR /&gt;&lt;BR /&gt;LANID="192.168.1.0/24"&lt;BR /&gt;DESID=x.y.z.w&lt;BR /&gt;#IPTABLES -I FORWARD 1 -s $LANID -d $DESID -j REJECT&lt;BR /&gt;&lt;BR /&gt;Above is not working and after changes its also not desplaying others entry in my previous configured IPTABLES enteries.&lt;BR /&gt;&lt;BR /&gt;Please ellaborat more clearly.&lt;BR /&gt;&lt;BR /&gt;Thank you very much for resolving my prob.&lt;BR /&gt;&lt;BR /&gt;Is there any option to put DNS for blocking.&lt;BR /&gt;&lt;BR /&gt;Regards,&lt;BR /&gt;MKS</description>
      <pubDate>Sat, 19 May 2007 05:58:28 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/security-related-block-perticular-site/m-p/5047776#M48541</guid>
      <dc:creator>monu_1</dc:creator>
      <dc:date>2007-05-19T05:58:28Z</dc:date>
    </item>
    <item>
      <title>Re: security related block perticular site</title>
      <link>https://community.hpe.com/t5/operating-system-linux/security-related-block-perticular-site/m-p/5047777#M48542</link>
      <description>&amp;gt;&amp;gt;&amp;gt; Above is not working and after changes its also not desplaying others entry in my previous configured IPTABLES enteries.&lt;BR /&gt;&lt;BR /&gt;Tha's weird. Can you post the output of:&lt;BR /&gt;&lt;BR /&gt;service iptables status&lt;BR /&gt;&lt;BR /&gt;Or&lt;BR /&gt;&lt;BR /&gt;iptables -nL FORWARD&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&amp;gt;&amp;gt;&amp;gt; Is there any option to put DNS for blocking.&lt;BR /&gt;&lt;BR /&gt;Depending of what do you want to block, if you want to restrict clients from using DNS, you have two options, block the port 53 for these clients, or add a rule in the named.conf to restrict the hosts that can query your dns server (if you have one).</description>
      <pubDate>Sat, 19 May 2007 10:09:00 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/security-related-block-perticular-site/m-p/5047777#M48542</guid>
      <dc:creator>Ivan Ferreira</dc:creator>
      <dc:date>2007-05-19T10:09:00Z</dc:date>
    </item>
    <item>
      <title>Re: security related block perticular site</title>
      <link>https://community.hpe.com/t5/operating-system-linux/security-related-block-perticular-site/m-p/5047778#M48543</link>
      <description>Hi All,&lt;BR /&gt;&lt;BR /&gt;I have done above task as&lt;BR /&gt;&lt;BR /&gt;iptables -A OUTPUT -s 192.168.1.0/24 -d x.y.z.w -j DROP&lt;BR /&gt;&lt;BR /&gt;and it is working now. But when i restart iptables service, its remove my above targeted entry from filter table.&lt;BR /&gt;&lt;BR /&gt;What shd i do that it will remains permanent in filter table even after reboot my system&lt;BR /&gt;&lt;BR /&gt;Regards,&lt;BR /&gt;MKS</description>
      <pubDate>Tue, 22 May 2007 07:00:41 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/security-related-block-perticular-site/m-p/5047778#M48543</guid>
      <dc:creator>monu_1</dc:creator>
      <dc:date>2007-05-22T07:00:41Z</dc:date>
    </item>
    <item>
      <title>Re: security related block perticular site</title>
      <link>https://community.hpe.com/t5/operating-system-linux/security-related-block-perticular-site/m-p/5047779#M48544</link>
      <description>If you use Red Hat or something similar, just use:&lt;BR /&gt;&lt;BR /&gt;service iptables save&lt;BR /&gt;&lt;BR /&gt;If you run another Linux distribution, it depends of how it loads the iptables services, but basically, you have to run:&lt;BR /&gt;&lt;BR /&gt;iptables-save &amp;gt; /path/to/file&lt;BR /&gt;&lt;BR /&gt;Where /path/to/file could be something like /etc/sysconfig/iptables.&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Tue, 22 May 2007 08:42:38 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/security-related-block-perticular-site/m-p/5047779#M48544</guid>
      <dc:creator>Ivan Ferreira</dc:creator>
      <dc:date>2007-05-22T08:42:38Z</dc:date>
    </item>
    <item>
      <title>Re: security related block perticular site</title>
      <link>https://community.hpe.com/t5/operating-system-linux/security-related-block-perticular-site/m-p/5047780#M48545</link>
      <description>Thread Closed</description>
      <pubDate>Tue, 22 May 2007 09:45:11 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/security-related-block-perticular-site/m-p/5047780#M48545</guid>
      <dc:creator>monu_1</dc:creator>
      <dc:date>2007-05-22T09:45:11Z</dc:date>
    </item>
  </channel>
</rss>

