Solved

sonicwall

Posted on 2010-08-31
7
987 Views
Last Modified: 2012-07-16
We have a Sonicwall 4060.  We get a lot of threats from outside the US, yet we don't do any business outside the US.

 Is it possible to tell the Sonicwall to simply DENY ALL REQUESTS/ALL TRAFFIC from IP addresses with an origination outside the US?

 thanks
0
Comment
Question by:paulterack2
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
7 Comments
 
LVL 20

Expert Comment

by:woolnoir
ID: 33568799
It seems not to be possible and even if it were i would be VERY much advising any clients of mine against it, you can never be 100% sure of the exact location of IP addresses (subnetting, especially for the larger IP allocations). At best it would need some form of RIPE lookup on a per packet basis which would be very intensive for a heavy traffic site. Aside from the potential for error and thus blocking wanted traffic the admin overhead would be intense.

I've had a quick look on some tech sheets incase im missing any new developments and from what i can see it isnt something that you can do on that device.
0
 
LVL 13

Expert Comment

by:IT-Monkey-Dave
ID: 33568997
What woolnoir said.  You would be creating a LOT of headaches if you tried to do this.
The firewall is blocking all uninvited traffic by default.  Are you trying to also block connections to "foreign" IPs even if they originate from requests from your network (i.e. your user clicks on a .uk url)?
0
 

Author Comment

by:paulterack2
ID: 33569019
Yes. We have ZERO need for anything outside the US at this time. I appreciate your comments. It's really just something I was thinking about, wondering if possible because I just see so many intrusion attempts, all originating outside the US.
0
Simple, centralized multimedia control

Watch and learn to see how ATEN provided an easy and effective way for three jointly-owned pubs to control the 60 televisions located across their three venues utilizing the ATEN Control System, Modular Matrix Switch and HDBaseT extenders.

 
LVL 20

Accepted Solution

by:
woolnoir earned 250 total points
ID: 33569039
You may be able to report on it, but with most firewalls even thats not possible. Just image that each connection attempt is potentially 100's maybe even more packets and for the report to be consistent a geo-ip lookup needs to happen on every ip - its a big undertaking.

Our proxy server (a bluecoat) offers the same feature set for web access... based on URL inspection, and the reporting engine of that dies when we ask for Geo-ip lookups - imagine that x 10000.
0
 
LVL 20

Expert Comment

by:woolnoir
ID: 33569049
It would be nice if there were a quick way to do it, i dont imagine RIPE would be too pleased either with the multiple order of magnitude increase on the number of IP queries they get... i'd see some evil humour in that one.
0
 
LVL 13

Assisted Solution

by:IT-Monkey-Dave
IT-Monkey-Dave earned 250 total points
ID: 33569051
I understand what you're getting at but the Internet is so "global" now (like everything else) that some of the content from a US-based site could be linked from just about anywhere in the world.  I would say disregard, firewall is operating as intended.
0
 
LVL 1

Expert Comment

by:papaschlumpf
ID: 38191626
there is a feature called Geo-IP Filtering. ( https://www.fuzeqna.com/sonicwallkb/consumer/kbdetail.asp?kbid=8963&formaction=catalert ) .
its possible with the new firmware 5.8.1.x ( for example the tz 210 or nsa 240, nsa 2400 ...) has it . Unfortunatly not the pro 4060.
0

Featured Post

Windows Server 2016: All you need to know

Learn about Hyper-V features that increase functionality and usability of Microsoft Windows Server 2016. Also, throughout this eBook, you’ll find some basic PowerShell examples that will help you leverage the scripts in your environments!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Shadow IT is coming out of the shadows as more businesses are choosing cloud-based applications. It is now a multi-cloud world for most organizations. Simultaneously, most businesses have yet to consolidate with one cloud provider or define an offic…
I had an issue with InstallShield not being able to use Computer Browser service on Windows Server 2012. Here is the solution I found.
Internet Business Fax to Email Made Easy - With  eFax Corporate (http://www.enterprise.efax.com), you'll receive a dedicated online fax number, which is used the same way as a typical analog fax number. You'll receive secure faxes in your email, f…
NetCrunch network monitor is a highly extensive platform for network monitoring and alert generation. In this video you'll see a live demo of NetCrunch with most notable features explained in a walk-through manner. You'll also get to know the philos…

724 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question