Lock Down Your Network Traffic - Block all outbound traffic except DNS and HTTP/S

  Рет қаралды 21,424

Willie Howe

Willie Howe

Күн бұрын

Пікірлер: 52
@ikke656
@ikke656 Жыл бұрын
I also always allow NTP, because things get confused/stop working when time is not within margins. Also STUN is more often needed for things like Teams, Webex and Zoom. STUN server is 3478 for UDP and TCP, and 5349 for TLS.
@canadianwildlifeservice8883
@canadianwildlifeservice8883 Жыл бұрын
Block outbound UDP 443, which is Google's QUIC protocol. UDP is faster for streaming media, but less secure. TCP is the standard protocol for port 443 and uses the three-way handshake for data integrity and security.
@canadianwildlifeservice8883
@canadianwildlifeservice8883 Жыл бұрын
@@WillieHowe @@WillieHowe If you knew more about how quic works instead of calling people trolls... you will know that browsers fallback to using TCP on 443 when UDP on port 80 and 443 is blocked.
@WillieHowe
@WillieHowe Жыл бұрын
​@@canadianwildlifeservice8883I had to reread your message and yes I agree that outright blocking quic on 443 UDP is a good idea. Would take one more firewall rule but totally doable. Thanks for hanging in there.
@rpinut
@rpinut Жыл бұрын
Hi Willie, I'm wondering how to block DNS exept for example a pihole. So 2 ip adresses on the network can go out. Maybe redirect DNS?
@glennmcelroy8282
@glennmcelroy8282 Жыл бұрын
Create an outbound rule that blocks port 53 for all IPs except those of your piehole(s).
@back2basics512
@back2basics512 7 ай бұрын
How to automatically block internet traffic to newly connected devices as i want to allow them internet access myself with their mac addresses
@daddycash7076
@daddycash7076 Жыл бұрын
I locked down my network and allowed some ports but port forwarding is not working. Is there anything I'm not doing right ?
@kristopherleslie8343
@kristopherleslie8343 Жыл бұрын
Willie think he slick lol he knows we wanna see the next video 😂❤
@georgiosstratigos4334
@georgiosstratigos4334 Жыл бұрын
Rule of thumb for me( on my setups on business environment) ..I only allow outgoing connections tcp/udp to 80/443/53/123/8080/5938 for teamviewer.. icmp echo req blocked of course..incoming connection (allow only established/accepted packets and drop invalid).. by the way congratulations for the video .keep going
@davidwright6105
@davidwright6105 Жыл бұрын
This did not work for me. All of my Echo devices will accept commands but won't turn on and off devices. I added port 8080 and 3478 to the list but no joy.
@PE4Doers
@PE4Doers Жыл бұрын
A very helpful video Willie 🙂
@tokoiaoben3842
@tokoiaoben3842 Жыл бұрын
For me I allowed only these ports 80, 443, 123, 53, 25, 465, 587, 110, 995 in my network. Does this kind of setup blocked bittorrents ?
@ikke656
@ikke656 Жыл бұрын
Bittorrent traffic is usually in the 50k range.
@mikescott4008
@mikescott4008 Жыл бұрын
QUIC used UDP/443 You are only blocking ports, not with protocol, correct?
@donvecchio6048
@donvecchio6048 Жыл бұрын
Good video.. does blocking these ports still allow incoming streaming services? Eg Disney+ etc thanks
@WillieHowe
@WillieHowe Жыл бұрын
If they use 80 or 443. My kid lost discord while I was doing this. 😂
@donvecchio6048
@donvecchio6048 Жыл бұрын
Thanks...will just have to try then...by the way, it's handy that you are using a UDR... I'm learning the Unifi system on a UDR at the moment and tossing up if it's worth moving the next level...so, good to be able to know that it can handle fairly advanced setup...
@WillieHowe
@WillieHowe Жыл бұрын
@@donvecchio6048 it can
@iamjamesxo
@iamjamesxo Жыл бұрын
Thank you for this tutorial, I'm new to networking. Question: I've applied these firewall rules, and I am running mullvad vpn configured on my router through open vpn, so everything going through my router is being routed through my vpn. When i test ports, it was open, allowing a connection using the test site you provided. I then paused my vpn and ports are closed, it will not load page using the test site provided. My primary concern is my internet traffic being monitored, or remote access and outbound routing. Should I not be running a vpn through my router ? I thought this was the most safe route, but it's still allowing outgoing connections so i will keep my current configuration if the vpn isn't necessary. thanks again. subscribed.
@WillieHowe
@WillieHowe Жыл бұрын
You can run VPN just make sure the ports allowed.
@mrwhosmynameagain
@mrwhosmynameagain Жыл бұрын
Who uses Google for news 😅 that's like using a sieve for water - you'll only get a filtered version of what's really there.
@D0n5023
@D0n5023 Жыл бұрын
Awesome content! Thank you! 😊
@markozoric2117
@markozoric2117 Жыл бұрын
Why would you filter outbound traffic? You are only overloading USG or UDM.
@WillieHowe
@WillieHowe Жыл бұрын
There are actually security frameworks that have you block a lot of outbound traffic.
@rdottwordottwo2286
@rdottwordottwo2286 Жыл бұрын
Nice informative video!
@davidm.8309
@davidm.8309 Жыл бұрын
Thank you very much. Also had to add Xbox ports for my kids. Ports 88, 3074, 500, 3544, 4500
@ikke656
@ikke656 Жыл бұрын
500 and 4500 are a bit curious. those are IPSEC VPN ports.
@serpent77
@serpent77 Жыл бұрын
Xbox is one of the "friendlier" game systems to allow access for like this because Ms tunnels back to the live servers for everything. On some AAA titles, they skip the live servers (I'm looking at you fortnite!) When they do its a nightmare trying to limit their access.
@sukihirako7240
@sukihirako7240 Жыл бұрын
keep it up nice video's learning alot thx :) can you make a tutorial how to control the dns also thx :)
@KSJNX
@KSJNX Жыл бұрын
Good for cryptominers and torrenting but be aware that most malware also uses 80/443 since it's a commonly open port.
@jamesa4958
@jamesa4958 Жыл бұрын
Thank you
@Polkster13
@Polkster13 Жыл бұрын
Yes, please on DNS control.
@bjarnenilsson80
@bjarnenilsson80 4 ай бұрын
And polecjes like this just make evry possible protocol tunnel over port 08 or 443 to "bypass thst pesky firewall" meaning you have to implement dpi etc: Note: I shuld hsve said makes evry application developer tunel...
@jpasayan
@jpasayan Жыл бұрын
Yes how to control dns video pls
@serpent77
@serpent77 Жыл бұрын
It's not hard, setup your pi hole or whatever devise you'll use for dns, change your dhcp to hand out that address for dns, lock port 53 (udp and tcp) to all devices except the pihole, and profit from local caching of dns, and filtering in the case of a pihole or manual intervention.
@serpent77
@serpent77 Жыл бұрын
If you're doing this on a home network and game, or have kids that game, have fun discovering how many game devs insist on wide open traffic in and outbound 😉👍
@serpent77
@serpent77 Жыл бұрын
Oh, and Nintendo is by far the worst. I had to assign a public ip nat to my son's switch and open traffic both ways for it.
@justindupuis180
@justindupuis180 Жыл бұрын
Noooo your breaking the internet, my school does this and it's a pain
@mrwhosmynameagain
@mrwhosmynameagain Жыл бұрын
Nice video thanks for sharing, but why would you lock down your network if you're gonna be using TikTok? Thats a massive security and privacy breach in and of itself. Doesn't make any sense
@WillieHowe
@WillieHowe Жыл бұрын
And yet here you are using a Google service 😂
@stentoft7600
@stentoft7600 Жыл бұрын
Dns crontrol
@WillieHowe
@WillieHowe Жыл бұрын
Listen a little further in and we talk about DNS.
@xephael3485
@xephael3485 Жыл бұрын
DNS lookups shouldn't be going out. They should be answered by internal server or relay. Also Google "Should I block ICMP" ... It should be allowed for PMTUD etc
@WillieHowe
@WillieHowe Жыл бұрын
Listen a little further in and we talk about DNS.
@xephael3485
@xephael3485 Жыл бұрын
@@WillieHowe I did, but it should have been brought up initially...way too many DNS abuses for it to have free reign externally
@dustinclark83
@dustinclark83 Жыл бұрын
How about no :))
@CarlMGregory
@CarlMGregory Жыл бұрын
No thanks
@c0p0n
@c0p0n Жыл бұрын
You need to stop smoking hubcap shavings mate.
@WillieHowe
@WillieHowe Жыл бұрын
Not sure what that means but I don't smoke anything.
Lock down DNS on your network
11:55
Willie Howe
Рет қаралды 20 М.
UniFi: How To Segregate Networks But Allow Printing
11:50
Willie Howe
Рет қаралды 6 М.
#behindthescenes @CrissaJackson
0:11
Happy Kelli
Рет қаралды 27 МЛН
Block QUIC - Tighten down your Internet traffic futher.
5:40
Willie Howe
Рет қаралды 7 М.
DNS Server Lockdown
17:37
Crosstalk Solutions
Рет қаралды 81 М.
never leave the terminal
5:53
NetworkChuck
Рет қаралды 148 М.
NEVER install these programs on your PC... EVER!!!
19:26
JayzTwoCents
Рет қаралды 4,8 МЛН
What does the UniFi firewall block by default?
6:12
Willie Howe
Рет қаралды 14 М.
Router Antenna Positions - What You're Doing Wrong
10:25
NetWork From Home
Рет қаралды 793 М.
Unifi Traffic Rules secure your network the easy way!
15:19
LoRes DIY
Рет қаралды 8 М.
#behindthescenes @CrissaJackson
0:11
Happy Kelli
Рет қаралды 27 МЛН