Firewall - Outgoing

Contents

Overview

Firewall Outgoing Information
Description Tool for blocking or allowing (depending on mode) outgoing connections on your network.
Package Name cc-firewall
Configuration Page Network > Firewall > Outgoing

Configuration

From the Firewall Outgoing page, you can block or allow certain kinds of traffic from leaving your network depending on the mode/policy.

 
 

As of ClarkConnect 4.0, it is now possible to reverse the meaning of rules created from the Firewall Outgoing page. The language used in the following documentation has been altered to reflect this change. Users of older ClarkConnect versions can only allow all outgoing traffic by default and then selectively block certain hosts and services. See Choose an Outgoing Mode below for more details.

 
 


This page is useful for blocking/allowing instant messenging, chat, peer-to-peer music dowloads, and more.

You have two ways to block/allow traffic:

  • by destination port/service
  • by destination IP address/domain

Note: If you want to block peer-to-peer file sharing programs like Kazaa and Limewire, you will also want to check the Firewall - Peer-to-Peer section of the user guide.

Choose an Outgoing Mode

As of ClarkConnect 4.0, you can toggle the outgoing traffic mode or policy. All previous versions of ClarkConnect allowed all outgoing traffic by default, only providing the administrator with the ability to specifically block certain hosts or services. With ClarkConnect 4.0 and above, it is possible to block all outgoing traffic by default and only open or allow certain destination domains, ports/services to be contacted.

Image:Ss_firewall_block_outgoing_mode.png

Note: These are the two Outgoing Traffic policies available as of ClarkConnect 4.0.

Outgoing Traffic - By Port/Service

Destination Ports prevents/allows a connection on a particular port/service. For instance, adding port 80 (web) disables/enables web-surfing for your entire local network.

Image:firewalloutgoingports.png

Outgoing Traffic - By Host/Destination

Destination Domains allows you to block/allow certain networks and sites. For instance, if your Outgoing Mode is set to allow all outgoing traffic, blocking windowsupdate.microsoft.com blocks Windows from connecting to the windows update site. Keep in mind, some sites use multiple servers to handle network traffic and are not easily blocked.

Warning! 
  If you block destinations with the firewall bear in mind that users of the proxy may not be blocked. If you require proxy users to be blocked, your best option is to block the destinations using the DansGuardian Content Filter Module.  
 


Image:firewalloutgoingdestinations.png

As of ClarkConnect 4.0, the Block/Allow by Destination form has changed slightly. The standard services drop-down box has been removed and merged into the Destination Ports form illustrated above.

Image:firewalloutgoingdestinations4x.png

Troubleshooting

Links

Retrieved from "http://wiki.clarkconnect.com/docs/Firewall_-_Outgoing"

This page has been accessed 7,120 times. This page was last modified on 4 January 2008, at 16:00.