blocking destination addresses

  Green

    Green

    Hello all
    is it possible to block some destination addresses (not URLs!) or address ranges like we're blocking destination ports ("blocked services") now?

    Thanks & Happy New Year!
  fabjan

    fabjan


    You can telnet to your WRT54G and type the following command :
    iptables -I FORWARD -d x.x.x.x -j DROP
    where x.x.x.x is the destination address you want to block.
    You can block more than one address with many iptables command ex:
    iptables -I FORWARD -d x.x.x.x -j DROP
    iptables -I FORWARD -d y.y.y.y -j DROP
    iptables -I FORWARD -d z.z.z.z -j DROP
    You can also block a range within a mask ex:
    iptables -I FORWARD -d x.x.x.x/24 -j DROP
    will block from x.x.x.0 to x.x.x.255
    You can put these commands in the firewall scripts to avoid the lose of these modification if the WRT54G reboot.

  Green

    Green

    thanks a lot - it works!
    Now I can block complete /24 network without specifying list of individual ports or services.
