OPNsense
  • Home
  • Help
  • Search
  • Login
  • Register

  • OPNsense Forum »
  • Archive »
  • 19.1 Legacy Series »
  • automatically block Intranet connections based on access behavior (19.4)
« previous next »
  • Print
Pages: [1]

Author Topic: automatically block Intranet connections based on access behavior (19.4)  (Read 3216 times)

fiterzs

  • Newbie
  • *
  • Posts: 26
  • Karma: 1
    • View Profile
automatically block Intranet connections based on access behavior (19.4)
« on: May 09, 2019, 03:05:34 am »

Hello everyone
I would like to set some rules in the Intranet. The number of external connections per IP cannot be more than 1000. If it exceeds 1000, the Internet access will be automatically blocked.
Logged

fiterzs

  • Newbie
  • *
  • Posts: 26
  • Karma: 1
    • View Profile
Re: automatically block Intranet connections based on access behavior (19.4)
« Reply #1 on: May 09, 2019, 06:02:40 am »
I did not find a way to block the number of internal links beyond the number
Logged

fiterzs

  • Newbie
  • *
  • Posts: 26
  • Karma: 1
    • View Profile
Re: automatically block Intranet connections based on access behavior (19.4)
« Reply #2 on: May 10, 2019, 04:33:04 am »
Is there a way to do this?
thanks
Logged

hbc

  • Hero Member
  • *****
  • Posts: 501
  • Karma: 47
    • View Profile
Re: automatically block Intranet connections based on access behavior (19.4)
« Reply #3 on: May 10, 2019, 09:03:53 am »
Quote from: fiterzs on May 10, 2019, 04:33:04 am
Is there a way to do this?
thanks

Hard to say. Your question sounds like: People may access maximum 1000 ips (per day/hour/lifetime?) and then internet is shut down forever. This will not work.

You can set rate limits in firewall rules for:
  • Maximum number of established connections per host (TCP only)
  • Maximum number of unique source hosts
  • Maximum new connections per host / per second(s) (TCP only)

If you want those hard limits to prevent unlimited surfing, maybe you should check captive portal. No restriction for max. ips, but you can restrict it per time.
Logged
Intel(R) Xeon(R) Silver 4116 CPU @ 2.10GHz (24 cores)
256 GB RAM, 300GB RAID1, 3x4 10G Chelsio T540-CO-SR

fiterzs

  • Newbie
  • *
  • Posts: 26
  • Karma: 1
    • View Profile
Re: automatically block Intranet connections based on access behavior (19.4)
« Reply #4 on: May 13, 2019, 08:47:02 am »
Thanks HBC

yes. That's what I want to do

The advanced part of the rule set, the manual is not very clear. But sometimes these features are useful.
Logged

  • Print
Pages: [1]
« previous next »
  • OPNsense Forum »
  • Archive »
  • 19.1 Legacy Series »
  • automatically block Intranet connections based on access behavior (19.4)
 

OPNsense is an OSS project © Deciso B.V. 2015 - 2024 All rights reserved
  • SMF 2.0.19 | SMF © 2021, Simple Machines
    Privacy Policy
    | XHTML | RSS | WAP2