DrayTek UK Users' Community Forum
Help, Advice and Solutions from DrayTek Users
Help with 2820Vn Firewall Filter Rules
- zappan
- Topic Author
- Offline
- New Member
Less
More
- Posts: 2
- Thank you received: 0
08 Nov 2009 19:41 #58723
by zappan
zappan
Help with 2820Vn Firewall Filter Rules was created by zappan
I would like help in setting up Filter Rules in the Draytek 2820Vn router
that has just been purchased. The manual and FAQ on this subject is not
helpful for novices like myself.
The router is up and running using a static IP address. I have a NAS server that I want to be able to access through the internet. I have set this up using one of the 5 static IP addresses. It has been placed in the DMZ zone and can be accessed using one of the router’s internal IP e.g 192.168.1.18
My only concern is that since this NAS device is in the DMZ area, I need to add further filters to protect it. However, I find it difficult to do what I want in the Allow and Block Rules Filter rules.
For example, I only want to access certain services on the NAS such as web, FTP 21, HTTP and HTTPS 80, 443.
I can access on my internal network but I am unable to access from outside (WAN). I have tried to create the following filter without luck to access HTTP. If however I untick Filter Set Rule 2 then I am able to access. I have set up a filter rule as follows:
Filter Set 2 Rule 2
Comment: Block All
Direction: from WAN > LAN
source ip = Any
destination ip = 192.168.1.18
service type = Any
fragments = Don’t Care
rule = block if no further match
Filter Set 2 Rule 3
Comment: Allow HTTP
Direction: from WAN > LAN
source ip = Any
destination ip = 192.168.1.18
service type = tcp, Port from any to 80
fragments = Don’t Care
rule = Pass Immediately
Whenever I try to access from outside, the server is being blocked. I have opened the port 80 in the open port section.
Would appreciate help with this. Thanks
that has just been purchased. The manual and FAQ on this subject is not
helpful for novices like myself.
The router is up and running using a static IP address. I have a NAS server that I want to be able to access through the internet. I have set this up using one of the 5 static IP addresses. It has been placed in the DMZ zone and can be accessed using one of the router’s internal IP e.g 192.168.1.18
My only concern is that since this NAS device is in the DMZ area, I need to add further filters to protect it. However, I find it difficult to do what I want in the Allow and Block Rules Filter rules.
For example, I only want to access certain services on the NAS such as web, FTP 21, HTTP and HTTPS 80, 443.
I can access on my internal network but I am unable to access from outside (WAN). I have tried to create the following filter without luck to access HTTP. If however I untick Filter Set Rule 2 then I am able to access. I have set up a filter rule as follows:
Filter Set 2 Rule 2
Comment: Block All
Direction: from WAN > LAN
source ip = Any
destination ip = 192.168.1.18
service type = Any
fragments = Don’t Care
rule = block if no further match
Filter Set 2 Rule 3
Comment: Allow HTTP
Direction: from WAN > LAN
source ip = Any
destination ip = 192.168.1.18
service type = tcp, Port from any to 80
fragments = Don’t Care
rule = Pass Immediately
Whenever I try to access from outside, the server is being blocked. I have opened the port 80 in the open port section.
Would appreciate help with this. Thanks
zappan
Please Log in or Create an account to join the conversation.
- lorian
- Offline
- Member
Less
More
- Posts: 190
- Thank you received: 0
09 Nov 2009 21:51 #58742
by lorian
Replied by lorian on topic Help with 2820Vn Firewall Filter Rules
You could try
Filter Set 2 Rule 2
Comment: Allow HTTP
Direction: from WAN > LAN
source ip = Any
destination ip = 192.168.1.18
service type = tcp, Port from any to 80
fragments = Don’t Care
rule = Pass Immediately
Filter Set 2 Rule 12
Comment: Block All
Direction: from WAN > LAN
source ip = Any
destination ip = 192.168.1.18
service type = Any
fragments = Don’t Care
rule = Block Immediately
Make the block rule 12 so you have room to fit in others before it.
You might consider using a VPN connection for better protection.
Filter Set 2 Rule 2
Comment: Allow HTTP
Direction: from WAN > LAN
source ip = Any
destination ip = 192.168.1.18
service type = tcp, Port from any to 80
fragments = Don’t Care
rule = Pass Immediately
Filter Set 2 Rule 12
Comment: Block All
Direction: from WAN > LAN
source ip = Any
destination ip = 192.168.1.18
service type = Any
fragments = Don’t Care
rule = Block Immediately
Make the block rule 12 so you have room to fit in others before it.
You might consider using a VPN connection for better protection.
Please Log in or Create an account to join the conversation.
- zappan
- Topic Author
- Offline
- New Member
Less
More
- Posts: 2
- Thank you received: 0
11 Nov 2009 12:40 #58775
by zappan
zappan
Replied by zappan on topic Firewall Filter Rules
Thanks Lorian.
I have done as you said and it is working now.
I will try out the VPN when I get home this evening. Would I be able to login to my NAS device from my office or anywhere if I use Draytek Smart Client VPN tool?
Regards
zappan
I have done as you said and it is working now.
I will try out the VPN when I get home this evening. Would I be able to login to my NAS device from my office or anywhere if I use Draytek Smart Client VPN tool?
Regards
zappan
zappan
Please Log in or Create an account to join the conversation.
Moderators: Chris, Sami
Copyright © 2024 DrayTek