Router Firewall question.

Sharky Forums


Results 1 to 10 of 10

Thread: Router Firewall question.

  1. #1
    Tiger Shark
    Join Date
    Jun 2003
    Location
    Suck-***, Colorado
    Posts
    949

    Router Firewall question.

    You know how you can create a HOST file, or place IP Addresses in your Restriced Zone and keep your computer from communicating with sites?
    Well... I was wondering if there's a router that will save that information for it's own Firewall, thus keeping me from having to configure every computer on my home network. Basically, absolutely no traffic to or from said IP Addresses... blocked at the Router.
    CASE: Antec P180 | CPU: Intel Core 2 Duo Extreme X6800 | M/B: BFG 680i SLI Motherboard (BIOS P26)
    Memory: Corsair Dominator DDR800 (2 x 1 Gig) Video: BFG Nvidia 8800 GTX | HD: 150 Gig Raptor
    Sound: On-board for Ventrillo, X-FI Gamer for games | Monitor: DELL 2407WFP

  2. #2
    Hammerhead Shark drs1771's Avatar
    Join Date
    Dec 2002
    Location
    Spanish Fork, Utah
    Posts
    1,609
    I have a Linksys WRT54G (Wireless) and it supports Website blocking by URL address. I imagine any Linksys with this version of firmware does. I can't speak for other brands, but I know this particular model does.
    drs1771
    Main rig: i7-2600K, Gigabyte GA-Z68XP-UD3-iSSD, 16GB Kingston Hyper X 1333, 320GB Seagate Sata 3.0 X2 (Raid 0), Intel 40GB SSD Cached (Intel Rapid Storage), ATi Radeon HD5700.


    "It's not the size of your sig that matters, its the size of your heatpipe..."

  3. #3
    Hammerhead Shark phelan1777's Avatar
    Join Date
    Mar 2003
    Location
    Phila, Pa
    Posts
    1,080
    I set up my girlfriends NetGear router, and there are options for blocking spefic IP,s sites with specific words, Instant messengers and a few other neat additives.
    QX6700 @ 2.9, 3.2, 3.4, not quite 3.7
    Brd_122-CK-NF68-A1_EVGA
    Opt_2X_Px-716SA_Plextor
    Psu_SST_75ZF_SilverStone
    Os_Xs_Os_&_Xp_Prp_XSOS
    Box_Stacker_810_Cooler_Master
    Ram_Crucial_Ballistix_PC28000
    Vga_eVGA_8800GTS_ SLI_EVGA
    Hdd_320GB_72K.10_74GB_Sata_Seagate/WD
    Rd-30/Pa120.3/LiTtLe RiVeR G5!/2X MCW60s/MCW30

    (My work in progress)
    Stacker SLACKER Thread
    I reject your reality and substitute it with my own. Adam- Myth Busters

  4. #4
    Hammerhead Shark cat5e's Avatar
    Join Date
    Oct 2003
    Location
    NYC
    Posts
    2,630
    The capacity of the Entry Level Routers to do so is limited to few addresses.

    So depending on what you want to block using the Host file is much more flexible.

    There are simple free programs that help in editing the Host file and you can easly copy it across you Network to each computer.

    http://www.mvps.org/winhelp2002/hosts.htm



    CAT5e
    Microsoft, MVP - Networking
    .

  5. #5
    Tiger Shark
    Join Date
    Jun 2003
    Location
    Suck-***, Colorado
    Posts
    949
    Pfft! I'm not a n00b... I know how to work a HOST file, and how to add sites to the restricted area by REG file. However, MY computers are not the only ones which use my home network- Lan gaming, ect. Also, if I decide to wipe my computer I don't want to have to worry with backing up my HOST file every time, ect.
    To me, it's much easier to just block the crap at the Router and forget about it.
    I'll look into the Routers mentioned above, thanks guys.
    CASE: Antec P180 | CPU: Intel Core 2 Duo Extreme X6800 | M/B: BFG 680i SLI Motherboard (BIOS P26)
    Memory: Corsair Dominator DDR800 (2 x 1 Gig) Video: BFG Nvidia 8800 GTX | HD: 150 Gig Raptor
    Sound: On-board for Ventrillo, X-FI Gamer for games | Monitor: DELL 2407WFP

  6. #6
    Mako Shark pudad's Avatar
    Join Date
    Jan 2002
    Posts
    3,701
    Quote Originally Posted by Nightlord
    Pfft! I'm not a n00b... I know how to work a HOST file, and how to add sites to the restricted area by REG file. However, MY computers are not the only ones which use my home network- Lan gaming, ect. Also, if I decide to wipe my computer I don't want to have to worry with backing up my HOST file every time, ect.
    To me, it's much easier to just block the crap at the Router and forget about it.
    I'll look into the Routers mentioned above, thanks guys.
    News flash, host files are for newbs.

    Go find an old box, install openbsd, and learn some of the rules for there PF firewall. Basically something like this would do (say the website you don't like is at 67.123.0.34):

    block out on $ext_iface from any to 67.123.0.34

    So I'd suggest learning this sort of thing, or buying a linksys wrt54g (the only good home solution if you as me, cisco owns linksys, and it runs linux, so it is a great router).

    Another good choice (a compromise between running nix on an old box as a router and having the more easy setup off the shelf router) is the m0n0wall project.

    Google is your friend.

    Good Luck dude.
    Last edited by pudad; 10-11-2005 at 04:53 AM.

  7. #7
    Tiger Shark
    Join Date
    Jun 2003
    Location
    Suck-***, Colorado
    Posts
    949
    lol. I'm not learning Linux... again. (EDIT: When I say 'again' I mean back in the mid-90's. Right about the time Win95 came out and put me to SERIOUS work as a computer geek. Linux, however, was just for playing with as most games didn't run on it even then.) When Linux gets more support for games, I'll make the move. Until then, I'm perfectly happy with Windows XP Pro. I haven't had spyware or a virus in a long time. Partly because of the n00b Hosts files I have on each machine, my Virus Scanner and Zonealarm firewall. Using another computer in such a way would be a waste to me... I look the kudos for "passing down" my old rigs. <GRIN>
    Inputting forbidden IPs directly into my router seems the best solution.
    Last edited by Nightlord; 10-11-2005 at 03:28 PM.
    CASE: Antec P180 | CPU: Intel Core 2 Duo Extreme X6800 | M/B: BFG 680i SLI Motherboard (BIOS P26)
    Memory: Corsair Dominator DDR800 (2 x 1 Gig) Video: BFG Nvidia 8800 GTX | HD: 150 Gig Raptor
    Sound: On-board for Ventrillo, X-FI Gamer for games | Monitor: DELL 2407WFP

  8. #8
    Mako Shark pudad's Avatar
    Join Date
    Jan 2002
    Posts
    3,701
    Quote Originally Posted by Nightlord
    lol. I'm not learning Linux... again. (EDIT: When I say 'again' I mean back in the mid-90's. Right about the time Win95 came out and put me to SERIOUS work as a computer geek. Linux, however, was just for playing with as most games didn't run on it even then.) When Linux gets more support for games, I'll make the move. Until then, I'm perfectly happy with Windows XP Pro. I haven't had spyware or a virus in a long time. Partly because of the n00b Hosts files I have on each machine, my Virus Scanner and Zonealarm firewall. Using another computer in such a way would be a waste to me... I look the kudos for "passing down" my old rigs. <GRIN>
    Inputting forbidden IPs directly into my router seems the best solution.

    Don't be idiotic. You aren't playing games on your nat/firewall box. Just go get one of those wrt54g routers.

  9. #9
    Tiger Shark
    Join Date
    Jun 2003
    Location
    Suck-***, Colorado
    Posts
    949
    Ok, I found some information on OpenWRT... way over my head.
    It sounds pretty badass in that it adds real funtionality to the Router... but I have absolutely no idea how to configure, compile, install it. Anyone know if there's a "ready-made" package to simplify the install and get it up and running?
    CASE: Antec P180 | CPU: Intel Core 2 Duo Extreme X6800 | M/B: BFG 680i SLI Motherboard (BIOS P26)
    Memory: Corsair Dominator DDR800 (2 x 1 Gig) Video: BFG Nvidia 8800 GTX | HD: 150 Gig Raptor
    Sound: On-board for Ventrillo, X-FI Gamer for games | Monitor: DELL 2407WFP

  10. #10
    Mako Shark pudad's Avatar
    Join Date
    Jan 2002
    Posts
    3,701
    Quote Originally Posted by Nightlord
    Ok, I found some information on OpenWRT... way over my head.
    It sounds pretty badass in that it adds real funtionality to the Router... but I have absolutely no idea how to configure, compile, install it. Anyone know if there's a "ready-made" package to simplify the install and get it up and running?

    I've used a fair ammount of the openwrt stuff. It is easy as hell, they literally do everything for you. All you have to do is install it (you gotta tftp it while it boots), no code hacking, nothing. Then when you finish installing it, there is this package system that lets you install plenty of stuff. I have it installed on one of my wrt54gs (used it for a school project last year, fun to work with), but my other 3 or 4 have the stock cisco firmware. The webconfiguration on the stock firmware has most of what an average person would need to configure (QoS, port forwards, blocking specific addresses). I'm telling you, just go buy the wrt54g and use the stock stuff, which works fine. The custom stuff is good if you want to configure the vlans, setup OSPF routing (rather than RIP protocol, which comes with it), or ipsec. But for the average firewall router, you are fine with the default stuff.

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •