DrayTek UK Users' Community Forum

Help, Advice and Solutions from DrayTek Users

draytek 2925 restrict management access from WAN

  • davids355
  • Topic Author
  • User
  • User
More
07 Jun 2017 18:25 #1 by davids355
Hi guys,
I have a draytek 2925 series with latest firmware installed (3.8.4.1).
I have two WAN links (WAN1 and WAN2) and load balancing set up. The two wan ports are just connected to two ADSL modems.

Anyway, my problem is that the Draytek management interface is accessible via the internet and I want to stop this from being so.

I went into system maintenance, management and I unticked Allow management from the Internet, however, even after doing this and rebooting, it is still accessible.

I am not using standard port for access, I changed it to 4433 as I was using 443 for something else, dont know if that is relevant.

Any help much appreciated

thanks
Dave

Please Log in or Create an account to join the conversation.

More
08 Jun 2017 11:02 #2 by admin3
The router's SSL VPN server is likely to be the cause of that - it's not possible to log in to the router's management interface through that interface, only SSL VPN Dial-In Users can log in through that interface.
If you want that to stop responding from the Internet, you can turn off the SSL VPN Server in [VPN and Remote Access] > [Remote Access Control]



Forum Administrator

Please Log in or Create an account to join the conversation.

  • davids355
  • Topic Author
  • User
  • User
More
08 Jun 2017 11:34 #3 by davids355

admin3 wrote: The router's SSL VPN server is likely to be the cause of that - it's not possible to log in to the router's management interface through that interface, only SSL VPN Dial-In Users can log in through that interface.
If you want that to stop responding from the Internet, you can turn off the SSL VPN Server in [VPN and Remote Access] > [Remote Access Control]



Ah, that was the other part that was confusing me - I was not able to log in to the management interface, even though it was showing up.
The problem was that I just needed to close that port really, for pci compliance.

Thanks, unticking ssl vpn from remote access control did the trick.

Please Log in or Create an account to join the conversation.