It seems like your browser didn't download the required fonts. Please revise your security settings and try again.
Barracuda CloudGen Firewall

This Firmware Version Is End-Of-Support

Documentation for this product is no longer updated. Please see End-of-Support for CloudGen Firewall Firmware for further information on our EoS policy.

How to Create a Deny Access Rule

  • Last updated on

A Deny access rule terminates matching network sessions by replying 'TCP-RST' for TCP requests, 'ICMP Port Unreachable' for UDP requests, or 'ICMP Denied by Filter' for other IP protocols. Because the remote host receives a reply, it knows that your system is up and running and protected by a firewall.

 Create a Deny Access Rule

  1. Go to FIREWALL > Access Rules.
  2. Click Add Access Rule to create a new rule. The Add Access Rule window opens.
  3. Select Deny as the Action.
  4. Enter a Name for the rule. E.g., ExampleDenyRule
  5. Specify the following settings that must be matched by the traffic to be handled by the access rule, and click + after each entry:
    • Source – The source addresses of the traffic.
    • Network Services – Select a service object, or select Any for this rule to match for all services.
    • Destination – The destination addresses of the traffic.
  6. (optional) Configure Advanced settings. For more information, see Advanced Access Rule Settings.
    deny_rule.png
  7. Click Save.
  8. Drag and drop the access rule so that it is the first rule that matches the traffic that you want it to forward. Ensure that the rule is located above the BLOCKALL rule; rules located below the BLOCKALL rule are never executed.

Additional Matching Criteria

Returning a Block Page for HTTP Traffic

Block and Deny access rules can return a block page if the user was blocked using the HTTP protocol on port 80. All other protocols and ports covered by the access rule will be blocked at TCP SYN level.

  1. Go to FIREWALL > Access Rules.
  2. Edit a Block access rule. The Edit Access Rule window opens.
  3. Click the Advanced tab.
  4. In the Other section, set HTTP Block Page to Access Block Page or Quarantine Block Page
  5. Click Save.

When a user is blocked by this access rule while using HTTP on port 80, the customizable Access Block Page is displayed. For more information, see How to Configure Custom Block Pages and Texts.
FW_Block_Rule_HTTP_Page.png