Google Groups no longer supports new Usenet posts or subscriptions. Historical content remains viewable.
Dismiss

IP Filtering

0 views
Skip to first unread message

Ben

unread,
Nov 12, 2001, 3:01:31 PM11/12/01
to
Hello All....

Not a guru by any means here.

We have a restricted FTP site, meaning you have to have a login and
password to get in.

One particular site I notice has tried many times to get into our FTP
site. The IP is always the same.

What I need to know is, is there a way to add that IP to a listing so that
it can never connect using Proxy Server?

Thanks


Keith W. McCammon

unread,
Nov 12, 2001, 3:04:53 PM11/12/01
to
Filter it at your border router, or using your firewall.


--
Keith W. McCammon


"Ben" <ben_h...@hotmail.com> wrote in message
news:tv0ajrf...@corp.supernews.com...

Ben

unread,
Nov 12, 2001, 3:31:53 PM11/12/01
to
How do you do that in MS Proxy 2.0?

"Keith W. McCammon" <k...@km.com> wrote in message
news:Ox5GWV7aBHA.2284@tkmsftngp05...

Keith W. McCammon

unread,
Nov 12, 2001, 3:51:09 PM11/12/01
to
To be brief: you don't. Proxy 2 has firewall functionality, but it is not a
true packet-filtering firewall. It was not designed or intended to work as
a rule-matching system, which is pretty much what you need to start allowing
disallowing certain IP addresses on source and destination

If you have a router, which you probably do, it can almost certainly do this
for you. I would suggest looking into that if you're that concerned about
this clown rooting out your system. Better still, I would get a firewall
and harden your system.

--
Keith W. McCammon


"Ben" <ben_h...@hotmail.com> wrote in message

news:tv0ccnj...@corp.supernews.com...

ZZZT

unread,
Nov 12, 2001, 4:16:25 PM11/12/01
to
Actually, Proxy Server IS a packet-filtering Firewall as well as an
application-gateway (Proxy). One can certainly disallow IP address from
entering. All one would need to do is to disallow whatever FTP site they
were worried about in the Properties of the FTP Site in MMC.

#1 Right-Click FTP Site
#2 Select "Properties"
#3 Click "Directory Security"
#4 Click the "Granted Access" radio button
#5 Click "Add", will which explicitly deny connections from a specific
computer.

Proxy 2.0 is very much a packet-filter Firewall. One would simply need to
click the Security button of either the Socks, Web or Winsock Proxy service
and se the choices given to you re: enabling packet filtering to win that
argument. And, Packet Filtering = Firewall. This product could certainly
have been called Microsoft Firewall 2.0.


Keith W. McCammon <k...@km.com> wrote in message

news:#3XDMv7aBHA.1856@tkmsftngp05...

Ben

unread,
Nov 12, 2001, 4:35:36 PM11/12/01
to
Ok... thanks.... I will give that a shot.

Were running on Proxy 2.0 now, but I do have ISA server that will probably
go online about Xmas time.

Also, my router, (Cisco 675) for the DSL connection... Im not sure how to
filter anything from that end.


"ZZZT" <ZZZT@no_spam.hotmail.com> wrote in message
news:Owsfv77aBHA.2328@tkmsftngp05...

phillip_windell

unread,
Nov 12, 2001, 4:51:25 PM11/12/01
to
1. Go to the Properties of the FTP site in IIS.
2. Select Directory Security
3. Select "Granted Access" (it should already be)
4. Click "Add"
5. Add the forbidden IP#s in the Exception box below.

--

Phillip Windell (MCP)
Network Administrator
WAND - TV
pwin...@wandtv.com
www.wandtv.com


"Ben" <ben_h...@hotmail.com> wrote in message
news:tv0ajrf...@corp.supernews.com...

Ben

unread,
Nov 12, 2001, 4:56:36 PM11/12/01
to
Thanks everyone!

Haha time to get that Unix box up and running <lol>

<Phillip Windell> wrote in message news:#PgPwQ8aBHA.1912@tkmsftngp03...

phillip_windell

unread,
Nov 12, 2001, 4:59:46 PM11/12/01
to
Well, I'm not totally disagreeing, but it is really a Proxy server with just
a certain amount of firewall capability built in to the same product. It
does not have true Application filtering ability even though it may give
that impression. It still filters by port# and protocol (TCP or UDP). It
does not do content filtering because it only looks at the packet itself and
not the internal content of the packet.

Application Filtering is much more complex and ISA server is more apt to fit
that role in terms of any of MS's "proxy" products.

"ZZZT" <ZZZT@no_spam.hotmail.com> wrote in message
news:Owsfv77aBHA.2328@tkmsftngp05...

phillip_windell

unread,
Nov 12, 2001, 5:02:29 PM11/12/01
to

"Ben" <ben_h...@hotmail.com> wrote in message
news:tv0hbi2...@corp.supernews.com...

> Thanks everyone!
>
> Haha time to get that Unix box up and running <lol>

Doing what you have asked in Proxy2 is extremely easy. If you have trouble
with that, I doubt you will have a prayer in getting a Unix baseb proxy
running.

0 new messages