Go Premium for a chance to win a PS4. Enter to Win

x
?
Solved

Is it reasonably safe to uncheck autoblock source of packets not handled?

Posted on 2008-10-02
2
Medium Priority
?
974 Views
Last Modified: 2013-11-16
Trying to troubleshoot some performance issues with a certain website that we subscribe to, I installed pingplotter at the suggestion of the vendor. Pinging/trace routing the site caused it to be blocked by our Firebox, due to the "autoblock source of packets not handled" option. Watchguard suggested that we uncheck  autoblock source of packets not handled and that it would be ok to do so.

What are the thoughts out there about this? I'm guessing it is probably OK to do so while I'm testing, but what about leaving it that way? Am I inadvertently blocking other legitimate sites? (I know, I should check the logs to answer that question).

There isn't really a solution to the Q - but I'd like to have some info to make an informed decision.

thanks for any input.
0
Comment
Question by:youngslim
2 Comments
 
LVL 32

Accepted Solution

by:
dpk_wal earned 800 total points
ID: 22626053
No problems in leaving that option disabled always; in the latest version of software and even in 9.x the option is disabled by default.

Let's first understand what this option implies; let's say you are not hosting any servers and by default all incoming traffic coming on the external interface of the firebox from the internet would be denied; if the option is enabled; in addition to denying the packets (default behavior no configuration needed for this) the firewall in addition block the source of packets and put them under blocked sites [System Manager->Blocked site tab]. If the option is disabled the firewall continues to deny the packet; just does not put the source of IP under blocked site.

What you loose; if you are a target of some port scan and the IP is under blocked list, then the firewall would not attempt to see if the rules permit/deny the requested port/protocol; thus saving CPU cycle.

Hope this help; please let know if you need more details.

Thank you.
0
 

Author Closing Comment

by:youngslim
ID: 31502443
That was a good, informative answer. Thanks,

0

Featured Post

Automating Your MSP Business

The road to profitability.
Delivering superior services is key to ensuring customer satisfaction and the consequent long-term relationships that enable MSPs to lock in predictable, recurring revenue. What's the best way to deliver superior service? One word: automation.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Large and small networks have one same need, Service monitoring. Service monitoring consists of watch services of the several servers in the network. To monitor means that the administrator will receive an alert when a service is down or it's state …
Load balancing is the method of dividing the total amount of work performed by one computer between two or more computers. Its aim is to get more work done in the same amount of time, ensuring that all the users get served faster.
There's a multitude of different network monitoring solutions out there, and you're probably wondering what makes NetCrunch so special. It's completely agentless, but does let you create an agent, if you desire. It offers powerful scalability …
NetCrunch network monitor is a highly extensive platform for network monitoring and alert generation. In this video you'll see a live demo of NetCrunch with most notable features explained in a walk-through manner. You'll also get to know the philos…
Suggested Courses
Course of the Month11 days, 19 hours left to enroll

916 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question