DrayTek UK Users' Community Forum
Help, Advice and Solutions from DrayTek Users
Block some devices from in/outgoing WAN access
- snissim
- Topic Author
- Offline
- New Member
Less
More
- Posts: 7
- Thank yous received: 0
06 Jan 2015 15:23 #82245
by snissim
Block some devices from in/outgoing WAN access was created by snissim
Hi,
I have a Vigor 2820Vn router and am hoping someone can direct me on how best to configure the built-in firewall to achieve the following:
I want to block certain LAN connected devices from having any outgoing internet access. E.g. I have a "Smart" TV and want it to connect to other devices on my internal LAN but do not want to give it access to connect to services outside my LAN - how is this best achieved? The Smart TV is just an example but I would like to apply this to other peripherals like Wifi printers etc.
Many Thanks for any advice.
I have a Vigor 2820Vn router and am hoping someone can direct me on how best to configure the built-in firewall to achieve the following:
I want to block certain LAN connected devices from having any outgoing internet access. E.g. I have a "Smart" TV and want it to connect to other devices on my internal LAN but do not want to give it access to connect to services outside my LAN - how is this best achieved? The Smart TV is just an example but I would like to apply this to other peripherals like Wifi printers etc.
Many Thanks for any advice.
Please Log in or Create an account to join the conversation.
- j1mbo
- Offline
- Member
Less
More
- Posts: 107
- Thank yous received: 0
06 Jan 2015 21:09 #82248
by j1mbo
Replied by j1mbo on topic Re: Block some devices from in/outgoing WAN access
Summary - specify the IP addresses of the devices to be blocked with DHCP reservations, then set firewall rules.
Say your network is 192.168.1.0/24 (192.168.1.0 to 192.168.1.255). Set the DHCP start address to 192.168.1.10 with 200 addresses (default).
Now in the DHCP server on the Draytek, find the devices to be filtered and provide them reserved addresses ('bind IP to MAC'). Give all the devices to be filtered adjacent addresses, say 192.168.1.100 to 192.168.1.120.
Then create an outbound firewall rule, direction: lan to wan, source: range, 192.168.1.100 to 192.168.1.120, destination: any, service: any, filter: Drop Immediate
Hope that helps!
Say your network is 192.168.1.0/24 (192.168.1.0 to 192.168.1.255). Set the DHCP start address to 192.168.1.10 with 200 addresses (default).
Now in the DHCP server on the Draytek, find the devices to be filtered and provide them reserved addresses ('bind IP to MAC'). Give all the devices to be filtered adjacent addresses, say 192.168.1.100 to 192.168.1.120.
Then create an outbound firewall rule, direction: lan to wan, source: range, 192.168.1.100 to 192.168.1.120, destination: any, service: any, filter: Drop Immediate
Hope that helps!
Please Log in or Create an account to join the conversation.
- snissim
- Topic Author
- Offline
- New Member
Less
More
- Posts: 7
- Thank yous received: 0
07 Jan 2015 01:49 #82254
by snissim
Replied by snissim on topic Re: Block some devices from in/outgoing WAN access
Thanks for the reply J1mbo.
As a test I tried applying this to my main PC's IP and it worked so many thanks.
As a test I tried applying this to my main PC's IP and it worked so many thanks.
Please Log in or Create an account to join the conversation.
Moderators: Chris
Copyright © 2025 DrayTek