DrayTek UK Users' Community Forum
Help, Advice and Solutions from DrayTek Users
limit port acess based on source IP address?
- protech
- Topic Author
- Offline
- New Member
Less
More
- Posts: 9
- Thank yous received: 0
01 Sep 2014 16:20 #81124
by protech
limit port acess based on source IP address? was created by protech
Hi,
I know the Vigor 2850 allows port redirection and open ports,
but can it be setup so that it only allows access to ports
listed in the port redirection or open ports, from specific
external IP addresses?
eg say I only wanted to allow RDP 3389 for the following 3 external IP addresses?
204.233.45.22
\
12.44.33.4
WAN:Vigor-2850:LAN
>Host PC.
53.33.4.235
/
If it's can do this then how?
Thank
PT
I know the Vigor 2850 allows port redirection and open ports,
but can it be setup so that it only allows access to ports
listed in the port redirection or open ports, from specific
external IP addresses?
eg say I only wanted to allow RDP 3389 for the following 3 external IP addresses?
204.233.45.22
\
12.44.33.4
WAN:Vigor-2850:LAN
>Host PC.
53.33.4.235
/
If it's can do this then how?
Thank
PT
Please Log in or Create an account to join the conversation.
- frag
- Offline
- Member
Less
More
- Posts: 115
- Thank yous received: 0
11 Sep 2014 13:55 #81214
by frag
Replied by frag on topic Re: limit port acess based on source IP address?
If i understand what youre asking for it should be achievable using the firewall rules.
Firstly you open the ports using the NAT menu.
Then you use the firewall to restrict access so only some public IP addresses can access those services.
You will need to configure 2 rules under the Default Data filter.
RULE 1
Direction WAN-LAN
Source: Trusted IP addresses
Destination: Any
Service: Any to 3389
Action: Pass Immediately
RULE 2
Direction WAN-LAN
Source: Any
Destination: Any
Service: Any to 3389
Action: Block Immediately
The first rule will allow all traffic from your trusted addresses through the firewall and the second rule will block all other public IP addresses. Amend these settings to suit the deployment.
Firstly you open the ports using the NAT menu.
Then you use the firewall to restrict access so only some public IP addresses can access those services.
You will need to configure 2 rules under the Default Data filter.
RULE 1
Direction WAN-LAN
Source: Trusted IP addresses
Destination: Any
Service: Any to 3389
Action: Pass Immediately
RULE 2
Direction WAN-LAN
Source: Any
Destination: Any
Service: Any to 3389
Action: Block Immediately
The first rule will allow all traffic from your trusted addresses through the firewall and the second rule will block all other public IP addresses. Amend these settings to suit the deployment.
Please Log in or Create an account to join the conversation.
- protech
- Topic Author
- Offline
- New Member
Less
More
- Posts: 9
- Thank yous received: 0
- sicon
- Offline
- Contributor
Less
More
- Posts: 642
- Thank yous received: 0
26 Sep 2014 16:17 #81292
by sicon
Did this work?
Replied by sicon on topic Re: limit port acess based on source IP address?
If i understand what youre asking for it should be achievable using the firewall rules.Frag wrote:
Firstly you open the ports using the NAT menu.
Then you use the firewall to restrict access so only some public IP addresses can access those services.
You will need to configure 2 rules under the Default Data filter.
RULE 1
Direction WAN-LAN
Source: Trusted IP addresses
Destination: Any
Service: Any to 3389
Action: Pass Immediately
RULE 2
Direction WAN-LAN
Source: Any
Destination: Any
Service: Any to 3389
Action: Block Immediately
The first rule will allow all traffic from your trusted addresses through the firewall and the second rule will block all other public IP addresses. Amend these settings to suit the deployment.
Did this work?
Please Log in or Create an account to join the conversation.
- protech
- Topic Author
- Offline
- New Member
Less
More
- Posts: 9
- Thank yous received: 0
31 Dec 2014 12:41 #82222
by protech
Replied by protech on topic Re: limit port acess based on source IP address?
Hi
Unfortunaltley no. Does anyone have any other ideas how to do this. On other firewalls it is straight forward.
Any ideas?
Thanks
Unfortunaltley no. Does anyone have any other ideas how to do this. On other firewalls it is straight forward.
Any ideas?
Thanks
Please Log in or Create an account to join the conversation.
- j1mbo
- Offline
- Member
Less
More
- Posts: 107
- Thank yous received: 0
31 Dec 2014 20:02 #82224
by j1mbo
Replied by j1mbo on topic Re: limit port acess based on source IP address?
The firewall on the Draytek is very odd - here's how I set this up.
If you have run out of entries in the Data Filter list, you can chain the rules onto another set. Personally I tend to have separate filter sets for Inbound and Outbound then the Data set (set 2) becomes just 1. xNetBIOS->DNS, 2. Inbound Rules, 3. Outbound Rules. But that's purely personal preference
The above posting should basically do the same but I've not tried it with open ports instead.
Hope that helps.
If you have run out of entries in the Data Filter list, you can chain the rules onto another set. Personally I tend to have separate filter sets for Inbound and Outbound then the Data set (set 2) becomes just 1. xNetBIOS->DNS, 2. Inbound Rules, 3. Outbound Rules. But that's purely personal preference
The above posting should basically do the same but I've not tried it with open ports instead.
Hope that helps.
Please Log in or Create an account to join the conversation.
Moderators: Chris
Copyright © 2025 DrayTek