Geo Block Firewall Settings - help!

Currently reading
Geo Block Firewall Settings - help!

Hello - I have a DS415+ - latest - DSM 6.2.4-25556 - everything up to date.

I've been getting login attempts on my mail (plus) server. They appear to be coming from Bulgaria according to WHOIS 5.188.206.xxx - a traceroute leaves me hanging somewhere around Amsterdam.

My Configuration:
* enabled the firewall, allowed local private ips and my static ip's (.248) from the ISP.
* created a rule to allow Germany to mail server since I use a mail server there for notifications, etc.
* created a rule to allow the United States and Minor Outlying access to several services (mail, dns, calendar, VPN, etc.)
* Finally I've created a rule to deny all ports, all protocols to all IP's
* created a rule to deny all on the 1st LAN (my public facing interface) should anything get past the All Interfaces settings.

All-Screenshot at 2021-07-27 12-29-56.png

LAN1 - DENY if no rules match.
LAN1-Screenshot at 2021-07-27 12-17-47.png

My firewall rules are NOT stopping the login attempts. I do have Auto-Block enabled, so after a couple of tries they have to get another IP address. This hacker apparently has the entire class c to use as they continue to try new IP addresses to get in.

What could be the problem with my configuration?
Thank you for your help!
ulyly
 
If you know the class C you could put a rule to deny it. I’d then place this rule low on the policy and gradually move it up until you find when attempts stop. That’ll show which rule isn’t working. Then leave it there.

For the Germany based mail notifications what I would look to do is limit this rule to just the IP range of its servers, not the whole of Germany.

Having a router with a properly definable firewall policy should help. Better if it has hit counters on rules… or a log of activity!
 
Upvote 0
Best to try this block on the router level. Do you have a firewall there as well?
Thank you Rusty - I'm working on a pfsense machine now! The Geo Blocking seems to work - cutting down on login attempts by 90% or more since I started using it. I'm a bit befuddled by this one getting through, thinking I had a good strategy with the config on the DSM.
If you know the class C you could put a rule to deny it. I’d then place this rule low on the policy and gradually move it up until you find when attempts stop. That’ll show which rule isn’t working. Then leave it there.
Thank you. A good troubleshooting tip!
For the Germany based mail notifications what I would look to do is limit this rule to just the IP range of its servers, not the whole of Germany.
I thought of that right after I posted this message :)
Having a router with a properly definable firewall policy should help. Better if it has hit counters on rules… or a log of activity!
Yes, again, working on a pfsense machine. The logs on synology are somewhat lacking from the gui standpoint.
 
Upvote 0

Create an account or login to comment

You must be a member in order to leave a comment

Create account

Create an account on our community. It's easy!

Log in

Already have an account? Log in here.

Similar threads

That's one way I suppose. For now, I just have a literally empty index.html file. As in NOTHING in it.
Replies
4
Views
2,600
If your router doesn't have an isolated guest network, just get another cheap wireless router, connect its...
Replies
11
Views
8,565
Closed ports + CG-NAT = Come at me, bros. :D
Replies
8
Views
8,366
Hello! Yes I did indeed find the problem, there are some special firewall rules that you need to make for...
Replies
4
Views
914
  • Question
OOOps running SRM 1.3.1 Update 6
Replies
1
Views
945
You are right. I think I'm getting this error because I can't allow cloudflared.
Replies
2
Views
1,290
All 3 NAS's are set that way.... FIREWALL AND NOTIFICATIONS ARE CHECKED I have in the past seen and...
Replies
2
Views
1,128

Welcome to SynoForum.com!

SynoForum.com is an unofficial Synology forum for NAS owners and enthusiasts.

Registration is free, easy and fast!

Trending threads

Back
Top