DrayTek UK Users' Community Forum

Help, Advice and Solutions from DrayTek Users

CSM : URL & Content Blocking / Filter Rules - 2710Vn

  • moggsie
  • Topic Author
  • Offline
  • Junior Member
  • Junior Member
More
13 Jul 2010 11:49 #1 by moggsie
Until recently, I was the owner of an ancient 2600We.

I decided to upgrade myself to a 2710VN.

Boy, was I in for a shock !

The old model provided a very simple way of blocking URL's that didn't match the criteria needed - there was no need to link them into your access control lists / filters . It just works.

On the newer object-orientated models such as the 2710, this is all reworked such that you really need to think more carefully about how you assemble your firewall filters.

The way Draytek have gone about this seems to have started off well, but has all the signs of a solution rushed to meet a deadline i.e. not finished off at all well.

example : Why allow a URL/Web Content filter to be added to a filter with only a "Pass" rule. Weird ? - well certainly confusing for newbies I'll bet !!

The best ( maybe only ? ) way I've found is to ...

1. start off with hard blocks..
2. then add a "block if no further match" filter rule.
3. then add rules to allow through things like SMTP/POP etc.
4. then when you come to allow through Web/Port 80/443, stick in a "Pass If No Further Match" rule for Port 80/443, which branches off to another Filter set ( when it matches the web rule ) that does further checking for nasty stuff using the URL/Web settings you can manage under CSM.

Anyone found an easier way ?

Please Log in or Create an account to join the conversation.

  • moggsie
  • Topic Author
  • Offline
  • Junior Member
  • Junior Member
More
11 Mar 2017 19:11 #2 by moggsie
Had to do this again today, after a long time ( 7 years ) between having to configure this stuff.

Trying to configure a new 2860 router & all my previous knowledge lost.

The official manual was totally dire for me & did not help in the slightest.

This however, did help much more.....

http://www.draytek.com/en/faq/faq-security/security.firewall/the-firewall-of-vigor-router/

...especially the flowcharts at the end.

Put it in the manual guys !!

Please Log in or Create an account to join the conversation.