DrayTek UK Users' Community Forum

Help, Advice and Solutions from DrayTek Users

Vigor 2960 Firewall Default

  • ber18578
  • Topic Author
  • Offline
  • New Member
  • New Member
More
30 Mar 2021 14:38 #1 by ber18578
Vigor 2960 Firewall Default was created by ber18578
Hello,
at the risk of exposing myself as a complete ignorant. What is the routers firewall doing to traffic from outside the internet if no rules are configured?
Regards
Bernhard

Please Log in or Create an account to join the conversation.

  • ber18578
  • Topic Author
  • Offline
  • New Member
  • New Member
More
30 Mar 2021 16:37 #2 by ber18578
Replied by ber18578 on topic Re: Vigor 2960 Firewall Default
To better specify, is Stateful Packet Inspection active per default or does it need a particular rule for activation?

Please Log in or Create an account to join the conversation.

  • hornbyp
  • User
  • User
More
31 Mar 2021 01:18 #3 by hornbyp
Replied by hornbyp on topic Re: Vigor 2960 Firewall Default

Ber18578 wrote:
To better specify, is Stateful Packet Inspection active per default or does it need a particular rule for activation?


Yes, it is (active).

In any case, the only "Open Ports" (ie in the NAT translation table), will be those that the Router had to 'open' in order to pass outbound traffic to the Internet. (Assuming of course, that Ports haven't been opened manually, Ports haven't been 'redirected' and no 'DMZ' host specified). So even with no firewall rules, there is very little/no? scope for unsolicited traffic to travel inbound.

Please Log in or Create an account to join the conversation.

  • ber18578
  • Topic Author
  • Offline
  • New Member
  • New Member
More
31 Mar 2021 07:54 #4 by ber18578
Replied by ber18578 on topic Re: Vigor 2960 Firewall Default
Thanks for the help,
does this apply to IPv6 traffic as well?

Please Log in or Create an account to join the conversation.

More
31 Mar 2021 09:42 #5 by piste basher
Replied by piste basher on topic Re: Vigor 2960 Firewall Default
I'm fairly sure that the "Block routing connections initiated from WAN" box for IPv6 is ticked by default. If it isn't suggest that you tick it....

Please Log in or Create an account to join the conversation.

  • ber18578
  • Topic Author
  • Offline
  • New Member
  • New Member
More
31 Mar 2021 10:24 #6 by ber18578
Replied by ber18578 on topic Re: Vigor 2960 Firewall Default
The Vigor2960 is a Linux based router so its configuartion interface doesn't have the tick box you are referring to. So thats why I was asking what happens if no Rules are defined, The default policy is "accept", that is why I was fearing that SPI on IPv6 traffic needs extra activation, although I couldn't find any means for enable/disable.

I want to setup IPv6 for a particular server for VoIP. i.e. one specific pass rule for this prefix on port 5060.

So that's why I was wondering if I can safely turn on IPv6 since I have active stateful packet inspection on IPv6 traffic.

Please Log in or Create an account to join the conversation.