DrayTek UK Users' Community Forum

Help, Advice and Solutions from DrayTek Users

Help with 2820Vn Firewall Filter Rules

  • zappan
  • Topic Author
  • Offline
  • New Member
  • New Member
More
08 Nov 2009 19:41 #1 by zappan
I would like help in setting up Filter Rules in the Draytek 2820Vn router
that has just been purchased. The manual and FAQ on this subject is not
helpful for novices like myself.

The router is up and running using a static IP address. I have a NAS server that I want to be able to access through the internet. I have set this up using one of the 5 static IP addresses. It has been placed in the DMZ zone and can be accessed using one of the router’s internal IP e.g 192.168.1.18

My only concern is that since this NAS device is in the DMZ area, I need to add further filters to protect it. However, I find it difficult to do what I want in the Allow and Block Rules Filter rules.

For example, I only want to access certain services on the NAS such as web, FTP 21, HTTP and HTTPS 80, 443.
I can access on my internal network but I am unable to access from outside (WAN). I have tried to create the following filter without luck to access HTTP. If however I untick Filter Set Rule 2 then I am able to access. I have set up a filter rule as follows:

Filter Set 2 Rule 2
Comment: Block All
Direction: from WAN > LAN
source ip = Any
destination ip = 192.168.1.18
service type = Any
fragments = Don’t Care
rule = block if no further match

Filter Set 2 Rule 3
Comment: Allow HTTP
Direction: from WAN > LAN
source ip = Any
destination ip = 192.168.1.18
service type = tcp, Port from any to 80
fragments = Don’t Care
rule = Pass Immediately

Whenever I try to access from outside, the server is being blocked. I have opened the port 80 in the open port section.
Would appreciate help with this. Thanks

zappan

Please Log in or Create an account to join the conversation.

More
09 Nov 2009 21:51 #2 by lorian
Replied by lorian on topic Help with 2820Vn Firewall Filter Rules
You could try

Filter Set 2 Rule 2
Comment: Allow HTTP
Direction: from WAN > LAN
source ip = Any
destination ip = 192.168.1.18
service type = tcp, Port from any to 80
fragments = Don’t Care
rule = Pass Immediately

Filter Set 2 Rule 12
Comment: Block All
Direction: from WAN > LAN
source ip = Any
destination ip = 192.168.1.18
service type = Any
fragments = Don’t Care
rule = Block Immediately

Make the block rule 12 so you have room to fit in others before it.

You might consider using a VPN connection for better protection.

Please Log in or Create an account to join the conversation.

  • zappan
  • Topic Author
  • Offline
  • New Member
  • New Member
More
11 Nov 2009 12:40 #3 by zappan
Replied by zappan on topic Firewall Filter Rules
Thanks Lorian.

I have done as you said and it is working now.

I will try out the VPN when I get home this evening. Would I be able to login to my NAS device from my office or anywhere if I use Draytek Smart Client VPN tool?

Regards

zappan

zappan

Please Log in or Create an account to join the conversation.

Moderators: Sami