DrayTek UK Users' Community Forum
Help, Advice and Solutions from DrayTek Users
2920n NAT feature: Restrict WAN Users by IP
- silentreproach
- Topic Author
- Offline
- New Member
Less
More
- Posts: 4
- Thank you received: 0
22 Jun 2013 01:48 #76760
by silentreproach
Dragging behind you the silent reproach of a million tear stained eyes. -Pink Floyd
2920n NAT feature: Restrict WAN Users by IP was created by silentreproach
We recently purchased 5 Vigor 2920n routers (spread around multiple offices) and one missing feature that is very important is to lock down incoming NAT by ip address. That is, some inbound ports need to be restricted to a specific WAN ip address or addresses.
For example, let's say we use NAT to allow incoming Remote Desktop port 3389 (again, just an example) and we want to restrict access so that only specific WAN ip addresses can connect on that port. Other routers, such as Netgear FVS338 allow the choice of either a single ip address, or range of ip addresses to have inbound access, per each defined port. Some routers even go so far as to allow a whilelist of ip addresses.
This would be awesome, please add this feature!
For example, let's say we use NAT to allow incoming Remote Desktop port 3389 (again, just an example) and we want to restrict access so that only specific WAN ip addresses can connect on that port. Other routers, such as Netgear FVS338 allow the choice of either a single ip address, or range of ip addresses to have inbound access, per each defined port. Some routers even go so far as to allow a whilelist of ip addresses.
This would be awesome, please add this feature!
Please Log in or Create an account to join the conversation.
- voodle
- Offline
- Big Contributor
Less
More
- Posts: 1139
- Thank you received: 0
22 Jun 2013 17:46 #76764
by voodle
Replied by voodle on topic Re: 2920n NAT feature: Restrict WAN Users by IP
That's not a missing feature imo, just use the firewall to achieve that.
Please Log in or Create an account to join the conversation.
- silentreproach
- Topic Author
- Offline
- New Member
Less
More
- Posts: 4
- Thank you received: 0
26 Jun 2013 13:21 #76806
by silentreproach
Dragging behind you the silent reproach of a million tear stained eyes. -Pink Floyd
Replied by silentreproach on topic Re: 2920n NAT feature: Restrict WAN Users by IP
How would you accomplish this with the firewall? I've looked at the interface and router manual, neither of which are terribly intuitive.
Please Log in or Create an account to join the conversation.
- silentreproach
- Topic Author
- Offline
- New Member
Less
More
- Posts: 4
- Thank you received: 0
22 Jul 2013 14:04 #77049
by silentreproach
Dragging behind you the silent reproach of a million tear stained eyes. -Pink Floyd
Replied by silentreproach on topic Re: 2920n NAT feature: Restrict WAN Users by IP
Anyone know how to do this?
Please Log in or Create an account to join the conversation.
- voodle
- Offline
- Big Contributor
Less
More
- Posts: 1139
- Thank you received: 0
23 Jul 2013 15:08 #77059
by voodle
Replied by voodle on topic Re: 2920n NAT feature: Restrict WAN Users by IP
here's a copy paste of an example:
If you have multiple IP addresses that you want to allow through the
firewall, you will need to go to Objects Setting then IP Objects,
click an index / link on there and add the IP address details (single
IP / subnet IP / range IP). You will need to do this for each IP
address that you want to allow if they are in separate IP ranges.
You can then add them to an IP Group under Objects Setting then IP
Group, select an index/link on there and add the IP Objects to the
group.
To configure the filter rules, go to the Firewall menu then Filter
Setup and on there go to #2 Default Data Filter and select the first
un-used filter rule:
Filter Rule #1:
Comment: Block SMTP
Direction: WAN to LAN
Source IP: leave this set to Any
Destination IP: leave this set to Any
Service Type: click Edit, select TCP, leave Source Port as 1-65535,
set Destination Port to 25-25, or create a Service Type
Object called SMTP with the same settings.
Action: Block if No Further Match
Filter Rule #2:
Comment: Allow SMTP
Direction: WAN to LAN
Source IP: click Edit and either specify the address you want to
allow, or set the Address Type to Group and Objects and select the IP
Group you created, then click OK.
Destination IP: leave this set to Any
Service Type: same as the previous rule
Action: Pass Immediately
That should then limit access to port 25 TCP to those IP addresses
only.
If you have multiple IP addresses that you want to allow through the
firewall, you will need to go to Objects Setting then IP Objects,
click an index / link on there and add the IP address details (single
IP / subnet IP / range IP). You will need to do this for each IP
address that you want to allow if they are in separate IP ranges.
You can then add them to an IP Group under Objects Setting then IP
Group, select an index/link on there and add the IP Objects to the
group.
To configure the filter rules, go to the Firewall menu then Filter
Setup and on there go to #2 Default Data Filter and select the first
un-used filter rule:
Filter Rule #1:
Comment: Block SMTP
Direction: WAN to LAN
Source IP: leave this set to Any
Destination IP: leave this set to Any
Service Type: click Edit, select TCP, leave Source Port as 1-65535,
set Destination Port to 25-25, or create a Service Type
Object called SMTP with the same settings.
Action: Block if No Further Match
Filter Rule #2:
Comment: Allow SMTP
Direction: WAN to LAN
Source IP: click Edit and either specify the address you want to
allow, or set the Address Type to Group and Objects and select the IP
Group you created, then click OK.
Destination IP: leave this set to Any
Service Type: same as the previous rule
Action: Pass Immediately
That should then limit access to port 25 TCP to those IP addresses
only.
Please Log in or Create an account to join the conversation.
Moderators: Chris, Sami
Copyright © 2024 DrayTek