Author Topic: SSL  (Read 2541 times)

mds

  • Zen Apprentice
  • *
  • Posts: 25
  • Karma: +0/-0
    • View Profile
SSL
« on: December 19, 2007, 01:18:47 pm »
Hi,

Hi Have on my installation blocked all TCP ports, so I can block P2P. But can't find where to open specific port's, such as 443 for ssl.

Everithing work's fine, except in some sites I can't opening it (such as www.google.com) or do a login.


Can anyone help me?

Thank's

Manuel.

javi

  • Zen Hero
  • *****
  • Posts: 1042
  • Karma: +0/-0
    • View Profile
Re: SSL
« Reply #1 on: December 19, 2007, 02:19:32 pm »
Hi,

Add as many rules and services as you need in Packet Filter -> Filtering rules for internal networks.  That rules are applied to the traffic coming out from your internal machines to the Internet

mds

  • Zen Apprentice
  • *
  • Posts: 25
  • Karma: +0/-0
    • View Profile
Re: SSL
« Reply #2 on: December 19, 2007, 05:07:04 pm »
Thank's for your reply.

My problem is wen adding a new rule I and select TCP, it won't letme choose port, ex: 443.


Ex:

Adding a new rule
Decision:   ACCEPT   
Source:   Qualquer
 Source Destination:   Qualquer
object     
Serviço:    any TCP // Here it chould be possible to open a specific port or range port   
Description:   

Thank's in advance

Manuel
   


sixstone

  • Zentyal Staff
  • Zen Hero
  • *****
  • Posts: 1417
  • Karma: +26/-0
    • View Profile
    • Sixstone's blog
Re: SSL
« Reply #3 on: December 20, 2007, 10:02:08 am »
Serviço:    any TCP // Here it chould be possible to open a specific port or range port   

Hi Manuel,

You may need to create your own services on Services menu entry by setting a service configured with destination port 443/tcp.

Thanks for using eBox!
My secret is my silence...

mds

  • Zen Apprentice
  • *
  • Posts: 25
  • Karma: +0/-0
    • View Profile
Re: SSL
« Reply #4 on: December 20, 2007, 01:17:50 pm »
Thank's for your reply.

I'm using eBox on my school and for now I'm loving it.

Opennig por 443 didn't work. I can't have acces Gmail or making login on hotmail.

let's put this other way.

I want to block p2p traffic on my network, Wat is the best way of doing that?

PS. Everithing else is working as I wanted (DHCP, transparent proxi and content filter).


Thank's in advance.

Manuel.

HANNES1985

  • Zen Warrior
  • ***
  • Posts: 141
  • Karma: +0/-0
    • View Profile
    • CSIWISP
Re: SSL
« Reply #5 on: July 03, 2008, 08:43:02 pm »
You can try to use your router to block p2p instead of ebox because p2p has too much ports to block and if your router does not support the p2p block you can setup your ebox just for ssl port 443 and http on port 80 you must create the service to edit it and remember to ad it to firewall packet filter.
Only people that wants to no more will ask!!