DrayTek UK Users' Community Forum
Help, Advice and Solutions from DrayTek Users
Inter-LAN Routing Query
- serious-it
- Topic Author
- Offline
- New Member
Less
More
- Posts: 5
- Thank you received: 0
14 May 2013 16:48 #76186
by serious-it
Inter-LAN Routing Query was created by serious-it
Hello Folks (its my first post, be kind!)
I have a Draytek 2830n and am trying to configure it to have a DMZ zone as well as the normal LAN . When I say DMZ, I just need a separate (secure) area to run a publicly facing web server. I need to allow this webserver to communicate on one TCP port with one server in the LAN - for the database/LOB system.
I've so far created VLAN0 (Ports 1,2,3) 192.x.x.x and VLAN1 (Port 4) 10.x.x.x
Checking the "Inter-LAN routing" has allowed traffic to flow between those VLANS.
I've setup a a Port Redirection rule for WAN HTTP traffic to the internal IP address of the server in the DMZ and to my slight surprise it's working great when tested.
All I would like to do now is stop any other traffic between those VLAN's (other than the one port to the database server). I've setup a new firewall filter to "block immediately" with direction LAN/RT/VPN > LAN/RT/VPN but it doesn't seem to be doing anything (can still RDP onto the webserver in the other VLAN).
Can anyone help please? I'm hoping a don't need to rely on windows software firewalls..:o
I have a Draytek 2830n and am trying to configure it to have a DMZ zone as well as the normal LAN . When I say DMZ, I just need a separate (secure) area to run a publicly facing web server. I need to allow this webserver to communicate on one TCP port with one server in the LAN - for the database/LOB system.
I've so far created VLAN0 (Ports 1,2,3) 192.x.x.x and VLAN1 (Port 4) 10.x.x.x
Checking the "Inter-LAN routing" has allowed traffic to flow between those VLANS.
I've setup a a Port Redirection rule for WAN HTTP traffic to the internal IP address of the server in the DMZ and to my slight surprise it's working great when tested.
All I would like to do now is stop any other traffic between those VLAN's (other than the one port to the database server). I've setup a new firewall filter to "block immediately" with direction LAN/RT/VPN > LAN/RT/VPN but it doesn't seem to be doing anything (can still RDP onto the webserver in the other VLAN).
Can anyone help please? I'm hoping a don't need to rely on windows software firewalls..
Please Log in or Create an account to join the conversation.
- serious-it
- Topic Author
- Offline
- New Member
Less
More
- Posts: 5
- Thank you received: 0
- serious-it
- Topic Author
- Offline
- New Member
Less
More
- Posts: 5
- Thank you received: 0
17 May 2013 12:02 #76233
by serious-it
Replied by serious-it on topic Re: Inter-LAN Routing Query
No-one knows if the Draytek 2830n router allows firewall rules between VLAN's ??!
Please Log in or Create an account to join the conversation.
- fryr
- Offline
- Junior Member
Less
More
- Posts: 24
- Thank you received: 0
29 Oct 2013 11:36 #78077
by fryr
Replied by fryr on topic Re: Inter-LAN Routing Query
This worked for me.
Creating a firewall rule that blocks traffic between the subnet address of one vlan and the single address of the other vlan did prevent traffic.
Creating a firewall rule that blocks traffic between the subnet address of one vlan and the single address of the other vlan did prevent traffic.
Please Log in or Create an account to join the conversation.
Moderators: Sami
Copyright © 2024 DrayTek