DrayTek UK Users' Community Forum
Help, Advice and Solutions from DrayTek Users
Firewall Lock down access to open port to specific IP
- digitalquill
- Topic Author
- Offline
- Junior Member
Less
More
- Posts: 12
- Thank you received: 0
08 Aug 2013 08:36 #77295
by digitalquill
Firewall Lock down access to open port to specific IP was created by digitalquill
Hi All
I have an issue with the Firewall setup of my Vigor 2860n.
I have NAT routing setup (working fine) and I want to limit access to that open port to one or more specified IP addresses.
I have setup a firewall rule as follows:
WAN -> LAN/RT/VPN
Source IP: !xxx.xxx.xxx.xxx (the external IP I want to allow - Note the !)
Destination IP: The Internal IP
Service Type: TCP, Port: from xxx to xxx
Fragments: Don't care
Filter: Block immediately
No Schedule is setup
NAT Routing is setup to allow the same port access to the same IP specified in the firewall
However, I can still access the service from a different IP address. I am obviously missing something here.
I assumed that the rule above, due to the ! said, 'block everything on this port apart from the specified IP'
Do I somehow need to block all traffic on everything? Again I had assumed that the firewall would do that by default
Any help or insight would be appreciated.
Thanks
Matt
I have an issue with the Firewall setup of my Vigor 2860n.
I have NAT routing setup (working fine) and I want to limit access to that open port to one or more specified IP addresses.
I have setup a firewall rule as follows:
WAN -> LAN/RT/VPN
Source IP: !xxx.xxx.xxx.xxx (the external IP I want to allow - Note the !)
Destination IP: The Internal IP
Service Type: TCP, Port: from xxx to xxx
Fragments: Don't care
Filter: Block immediately
No Schedule is setup
NAT Routing is setup to allow the same port access to the same IP specified in the firewall
However, I can still access the service from a different IP address. I am obviously missing something here.
I assumed that the rule above, due to the ! said, 'block everything on this port apart from the specified IP'
Do I somehow need to block all traffic on everything? Again I had assumed that the firewall would do that by default
Any help or insight would be appreciated.
Thanks
Matt
Please Log in or Create an account to join the conversation.
- voodle
- Offline
- Big Contributor
Less
More
- Posts: 1139
- Thank you received: 0
08 Aug 2013 11:29 #77299
by voodle
Replied by voodle on topic Re: Firewall Lock down access to open port to specific IP
the filter setup looks good but make sure you've got the source ports set to 1-65535 (because they're usually random) and only specify the destination port.
Also make sure the filter set that you put the rule in is linked to from the default data filter (filter set #2) by setting the next filter set option
Also make sure the filter set that you put the rule in is linked to from the default data filter (filter set #2) by setting the next filter set option
Please Log in or Create an account to join the conversation.
- digitalquill
- Topic Author
- Offline
- Junior Member
Less
More
- Posts: 12
- Thank you received: 0
08 Aug 2013 11:43 #77302
by digitalquill
Replied by digitalquill on topic Re: Firewall Lock down access to open port to specific IP
Thanks Voodle, I got there by trial and error... not ideal on a live system but got there.
I also had an issue where our website was calling back to stock control on an IP other than that revealed by pinging the domain name.
Thanks for your help
Matt
I also had an issue where our website was calling back to stock control on an IP other than that revealed by pinging the domain name.
Thanks for your help
Matt
Please Log in or Create an account to join the conversation.
Moderators: Chris, Sami
Copyright © 2024 DrayTek