On Sun, Jan 22, 2017 at 07:18:13PM +0100, qube...@tutanota.com wrote:
> Qubes 3.2
> Have created new AppVM and within "firewall rules" restricted access using 
> "deny access" to all websites [by leaving it blank] orĀ  just a single 
> website. Bizarrely however,the firewall lets all traffic thro'
> Any ideas
> 

Do you have the qube connected to a firewall, or directly to sys-net?

If the latter, then sys-net (by default) does not implement the Qubes
firewall.

If the former, open a console in the firewall and look at the relevant
rules :
iptables -L -nv
Are there rules allowing the traffic from the relevant IP in the FORWARD
chain?

Try changing the netvm for the relevant qube - make sure the iptables
rules change on the firewall. Then try reconnecting.
You can do this on command line using:
qvm-prefs <name> netvm -s none
and 
qvm-prefs <name> netvm -s <firewall>


-- 
You received this message because you are subscribed to the Google Groups 
"qubes-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to qubes-users+unsubscr...@googlegroups.com.
To post to this group, send email to qubes-users@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/qubes-users/20170122205558.GA8262%40thirdeyesecurity.org.
For more options, visit https://groups.google.com/d/optout.

Reply via email to