DrayTek UK Users' Community Forum
Help, Advice and Solutions from DrayTek Users
2860n Filter rules confusion - please help
- icarusbop
- Topic Author
- Offline
- Junior Member
Less
More
- Posts: 24
- Thank yous received: 0
27 Jan 2016 12:15 #85179
by icarusbop
2860n Filter rules confusion - please help was created by icarusbop
Hello:
I am having difficulty with setting up a filter rule, the manual is not very clear in this area, I hope you can clarify an area of confusion for me:
Here is a copy of the Rules set page from my router 2860n
https://www.dropbox.com/s/txxr66l6k7sxl0f/vg1.png?dl=0
Selecting filter rule 1/2/3 etc. takes me to the rule setup page…
https://www.dropbox.com/s/mj5g0z2qsn9t80z/vg2.png?dl=0
This page is where the confusion is:
The area in the Green border is the name, enabled status and scheduler of the rule – this is OK
The area in the Yellow border is the traffic type, direction and IP range of the rule – this is OK
The area in Red border is the rule application containing the area in Purple border the filter action – this is confusing.
When I change the selection in Purple – does it apply to the rest of the section in RED OR does it apply to a different rule in the filer set?
Examples:
Purple section set to “Pass immediately”
This passes all packets – but presumably only ones that match the other areas in the Red section
Purple section set to “Block immediately”
Why does the rest of the Red section become disabled (greyed out)?
I cannot change anything else in the RED section – so this rule cannot be applied to a URL content filter.
Purple section set to “Pass if no further match”
Does this mean pass if there is no further match in the RED section of this rule OR
Pass if there is no further match with rules 3/4/5 etc? In the Rules SET? (but it only applies to traffic that complies with the RED section – therefore you could apply this to a URL filter only)
Purple section set to “Block if no further match”
As above but block instead of pass
Any help is much appreciated.
Ian
I am having difficulty with setting up a filter rule, the manual is not very clear in this area, I hope you can clarify an area of confusion for me:
Here is a copy of the Rules set page from my router 2860n
Selecting filter rule 1/2/3 etc. takes me to the rule setup page…
This page is where the confusion is:
The area in the Green border is the name, enabled status and scheduler of the rule – this is OK
The area in the Yellow border is the traffic type, direction and IP range of the rule – this is OK
The area in Red border is the rule application containing the area in Purple border the filter action – this is confusing.
When I change the selection in Purple – does it apply to the rest of the section in RED OR does it apply to a different rule in the filer set?
Examples:
Purple section set to “Pass immediately”
This passes all packets – but presumably only ones that match the other areas in the Red section
Purple section set to “Block immediately”
Why does the rest of the Red section become disabled (greyed out)?
I cannot change anything else in the RED section – so this rule cannot be applied to a URL content filter.
Purple section set to “Pass if no further match”
Does this mean pass if there is no further match in the RED section of this rule OR
Pass if there is no further match with rules 3/4/5 etc? In the Rules SET? (but it only applies to traffic that complies with the RED section – therefore you could apply this to a URL filter only)
Purple section set to “Block if no further match”
As above but block instead of pass
Any help is much appreciated.
Ian
Please Log in or Create an account to join the conversation.
- fchef
- Offline
- Banned
Less
More
- Posts: 65
- Thank yous received: 0
28 Jan 2016 21:56 #85190
by fchef
Replied by fchef on topic Re: 2860n Filter rules confusion - please help
First of all you should add rules from set2 (data filter) and not set 1
Forget the area in Red border (it is for additional setting), just focus on the purple setting
Block if no further much and Pass if no further match requires that you have another following filter rule2
Look at my example. My goal is to have all dns traffic via opendns for web filtering. If someone changes his PC's dns to google's 8.8.8.8 to avoid web filtering then he will not have internet (DNS) access.
So my rule 2 blocks all dns traffic except for dns traffic going to servers as specified in rule 3
You can also do it the classic way. Make rule 2 allow opendns traffic, and make rule3 block all dns traffic
https://www.dropbox.com/s/so7dwcuvhf33ozr/1.jpg?dl=0
https://www.dropbox.com/s/d3zxlv8ou7iqhjv/2.jpg?dl=0
https://www.dropbox.com/s/jfj5n4uyjo51zjw/3.jpg?dl=0
Forget the area in Red border (it is for additional setting), just focus on the purple setting
Block if no further much and Pass if no further match requires that you have another following filter rule2
Look at my example. My goal is to have all dns traffic via opendns for web filtering. If someone changes his PC's dns to google's 8.8.8.8 to avoid web filtering then he will not have internet (DNS) access.
So my rule 2 blocks all dns traffic except for dns traffic going to servers as specified in rule 3
You can also do it the classic way. Make rule 2 allow opendns traffic, and make rule3 block all dns traffic
Please Log in or Create an account to join the conversation.
- icarusbop
- Topic Author
- Offline
- Junior Member
Less
More
- Posts: 24
- Thank yous received: 0
29 Jan 2016 08:01 #85195
by icarusbop
Replied by icarusbop on topic Re: 2860n Filter rules confusion - please help
fchef:
Thanks for your replay and the example - I think I see how it works a bit better now, the purple border setting references other rules from the same set.
BTW - good idea with the DNS filter - I never thought of that - I'll think I'll give it a go.
Regards:
Ian
Thanks for your replay and the example - I think I see how it works a bit better now, the purple border setting references other rules from the same set.
BTW - good idea with the DNS filter - I never thought of that - I'll think I'll give it a go.
Regards:
Ian
Please Log in or Create an account to join the conversation.
Moderators: Chris
Copyright © 2025 DrayTek