Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Highlighted

Time Limits Not Killing Active Connections

Hello,

I'm running R80.30 and I have a rule setup to drop any traffic from a specific IP range to the Internet, every day from Midnight until 0600.

The rule is working and does not allow any new connections during that time, but it doesn't drop active connections. In SmartView Tracker, I can see a few connections still open from that IP range, and users are still online.  I have to use the Block Intruder feature and drop the connection for 5 minutes. New connections are not allowed at that point until 0600.

Is there a way for the rule to drop active connections?  Or will I have to run some kind of script to accomplish this?

0 Kudos
4 Replies
Highlighted
Admin
Admin

You'll have to run some sort of script to do it.
It would probably be a fairly simple crontab using fw samp or similar.
0 Kudos
Highlighted

Agree with Phoneboy here that you will need to use a script, time ranges are only checked as a rule matching condition at connection start time, and never checked again once the connection is initially allowed.

R80.40 addendum for book "Max Power 2020" now available
for free download at http://www.maxpowerfirewalls.com
0 Kudos
Highlighted

Thanks @PhoneBoy & @Timothy_Hall.

Would this work?

Scheduled Job on GAIA web management on Gateway.  Command to run: fw sam -t 300 -J subsrc <IP> <Netmask>

0 Kudos
Highlighted

Did some testing and it seems to work with this:

Scheduled Job on Gateway GAIA Portal. Command to run: source /etc/profile.d/CP.sh ; fw sam -t 300 -J subsrc <IP> <Netmask>

0 Kudos