Re: Qustion about blcoking ips with ipsecpol

From: Herb Martin (news_at_LearnQuick.com)
Date: 02/26/05

  • Next message: S. Pidgorny : "Re: Active Directory User Object certificate store to personal certificate store"
    Date: Sat, 26 Feb 2005 13:05:15 -0600
    
    

    "Louis Schreyer" <info@aquarix.de> wrote in message
    news:cvpjuj$thl$1@online.de...
    > Hello again,
    >
    > can someone tell me which priority blocking filters have in respect to
    rules
    > in ipsecpol which open specific ports?

    The same. It depends on the SPECIFICITY mostly.

    > My problem is:
    > I have one rule "Block all traffic" which block anything
    > Then there are some rules opening ports for http, smtp and pop3.

    Yes.

    > Then I want to block several IP ranges, but this does not seem to work,
    > because the opener-rules seem to have priority.

    If you put in a SPECIFIC IP and a specific port block
    it should take precendence I believe.

    (If you opened 80, then close 80 for that address.)

    > How can I open a port to all except a specific ip range in ipsecpol?

    -- 
    Herb Martin
    >
    > Louis
    >
    >
    

  • Next message: S. Pidgorny : "Re: Active Directory User Object certificate store to personal certificate store"