DrayTek UK Users' Community Forum
Help, Advice and Solutions from DrayTek Users
Firewall not blocking (2850)
- lesd
- Topic Author
- Offline
- Member
Less
More
- Posts: 130
- Thank yous received: 0
11 Dec 2013 06:34 #78470
by lesd
Les
Replied by lesd on topic Re: Firewall not blocking (2850)
I think I now know the cause of this problem.
I actually have two Internet lines - WAN1 and WAN2 - and I have done separate Open Ports on each (as an Open Port is WAN specific [why there is no option for 'All' is an other topic])
The firewall rules and other associated objects (Service Types) are not WAN specific (WAN is not specified).
I assumed that the firewall rules applied to both WANs.
It seems that WAN2 is not being filtered by the firewall!!!??
If I turn off the open ports on WAN2 then the attacks stop. If I open them for WAN2 then within a few minutes the attacks start again.
I actually have two Internet lines - WAN1 and WAN2 - and I have done separate Open Ports on each (as an Open Port is WAN specific [why there is no option for 'All' is an other topic])
The firewall rules and other associated objects (Service Types) are not WAN specific (WAN is not specified).
I assumed that the firewall rules applied to both WANs.
It seems that WAN2 is not being filtered by the firewall!!!??
If I turn off the open ports on WAN2 then the attacks stop. If I open them for WAN2 then within a few minutes the attacks start again.
Les
Please Log in or Create an account to join the conversation.
- sicon
- Offline
- Contributor
Less
More
- Posts: 642
- Thank yous received: 0
11 Dec 2013 11:11 #78471
by sicon
Replied by sicon on topic Re: Firewall not blocking (2850)
Cool, glad you are getting somewhere
Both WANs should be filters by the firewall, are you on the latest firmware.
Id log a support case with Draytek if the filter is only working on 1 interface.
Both WANs should be filters by the firewall, are you on the latest firmware.
Id log a support case with Draytek if the filter is only working on 1 interface.
Please Log in or Create an account to join the conversation.
- lesd
- Topic Author
- Offline
- Member
Less
More
- Posts: 130
- Thank yous received: 0
11 Dec 2013 12:35 #78476
by lesd
Les
Replied by lesd on topic Re: Firewall not blocking (2850)
I am on 3.6.3
I was on 3.6.4 but that had issues so I reverted back.
I understand that the international site has a later driver but the UK site still is showing 364 which I assume is still the old one.
I will raise a case with support.
Thanks for your help.
I was on 3.6.4 but that had issues so I reverted back.
I understand that the international site has a later driver but the UK site still is showing 364 which I assume is still the old one.
I will raise a case with support.
Thanks for your help.
Les
Please Log in or Create an account to join the conversation.
- lintentech
- Offline
- Banned
Less
More
- Posts: 5
- Thank yous received: 0
24 Dec 2013 09:45 #78573
by lintentech
Replied by lintentech on topic Re: Firewall not blocking (2850)
having a slimier issue, I need to block SMTP Port 25 from all but one IP (92.63.133.169) so have setup the following rule:
Direction: WAN > LANRT/VPN
Source IP: !92.63.133.169
Destination IP: ANY
Service Type: TCP. Port from 25 to 25
Filter: Block Immediately
yet i can still connect from any IP
Direction: WAN > LANRT/VPN
Source IP: !92.63.133.169
Destination IP: ANY
Service Type: TCP. Port from 25 to 25
Filter: Block Immediately
yet i can still connect from any IP
Please Log in or Create an account to join the conversation.
- sicon
- Offline
- Contributor
Less
More
- Posts: 642
- Thank yous received: 0
24 Dec 2013 10:24 #78574
by sicon
Replied by sicon on topic Re: Firewall not blocking (2850)
that rule will block anything from the IP you want to pass on port 25
You need two rules
Direction: WAN > LANRT/VPN
Source IP: ANY
Destination IP: ANY
Service Type: TCP. Port from 25 to 25
Filter: Block Unless Further Match
Direction: WAN > LANRT/VPN
Source IP: ANY
Destination IP: 92.63.133.169
Service Type: TCP. Port from 25 to 25
Filter: Pass Immediately
You need two rules
Direction: WAN > LANRT/VPN
Source IP: ANY
Destination IP: ANY
Service Type: TCP. Port from 25 to 25
Filter: Block Unless Further Match
Direction: WAN > LANRT/VPN
Source IP: ANY
Destination IP: 92.63.133.169
Service Type: TCP. Port from 25 to 25
Filter: Pass Immediately
Please Log in or Create an account to join the conversation.
- lintentech
- Offline
- Banned
Less
More
- Posts: 5
- Thank yous received: 0
24 Dec 2013 11:25 #78575
by lintentech
Thanks for taking the time to post. But if you look closely there is a ! in front on the IP which I believe is any other then 92.63.133.169
However I have setup the two rules as you described and still traffic is allowed through from any address
Replied by lintentech on topic Re: Firewall not blocking (2850)
that rule will block anything from the IP you want to pass on port 25sicon wrote:
Thanks for taking the time to post. But if you look closely there is a ! in front on the IP which I believe is any other
However I have setup the two rules as you described and still traffic is allowed through from any address
Please Log in or Create an account to join the conversation.
Moderators: Chris
Copyright © 2025 DrayTek