DrayTek UK Users' Community Forum
Help, Advice and Solutions from DrayTek Users
Any idea how to restrict dial in users to one tcp protocol?
- roga
- Topic Author
- Offline
- Junior Member
Less
More
- Posts: 17
- Thank yous received: 0
08 Aug 2019 19:53 #94836
by roga
Any idea how to restrict dial in users to one tcp protocol? was created by roga
I have a 255.255.255.0 lan, which awards dial in users with an ip address on the subnet. (Draytek 2860)
Is there a way to have a firewall rule to allow only one tcp protocol for dial in users?
What I want to do is restrict access to only remote desktop server service ( which I can define as answering to a particular tcp port) as I don't want dial in users to be able to see the rest of the network.
regards
Roga
Is there a way to have a firewall rule to allow only one tcp protocol for dial in users?
What I want to do is restrict access to only remote desktop server service ( which I can define as answering to a particular tcp port) as I don't want dial in users to be able to see the rest of the network.
regards
Roga
Please Log in or Create an account to join the conversation.
- admin3
- Offline
- Site Admin
Less
More
- Posts: 604
- Thank yous received: 0
09 Aug 2019 09:12 #94839
by admin3
Forum Administrator
Replied by admin3 on topic Re: Any idea how to restrict dial in users to one tcp protocol?
It appears the UK site doesn't have an equivalent guide yet, but this article shows how to do what you want to do, which is to use the router's firewall on either side to limit access to a single IP on the remote VPN subnet:
https://www.draytek.com/support/knowledge-base/5470
Forum Administrator
Please Log in or Create an account to join the conversation.
- roga
- Topic Author
- Offline
- Junior Member
Less
More
- Posts: 17
- Thank yous received: 0
09 Aug 2019 16:33 #94847
by roga
Replied by roga on topic Re: Any idea how to restrict dial in users to one tcp protocol?
Thanks @admin3 for the suggestion. The document you link to is for Lan to Lan VPN, in this case I am using what draytek refer to as "Remote Dial in User", so if you have any ideas about that I would be pleased to hear them.
regards
Roger
regards
Roger
Please Log in or Create an account to join the conversation.
- admin3
- Offline
- Site Admin
Less
More
- Posts: 604
- Thank yous received: 0
12 Aug 2019 09:29 #94855
by admin3
Forum Administrator
Replied by admin3 on topic Re: Any idea how to restrict dial in users to one tcp protocol?
Good point, the setup is about the same, but you put the LAN IP range as the IP range that the remote dial-in users will use, so you'd block "LAN/RT/VPN > LAN/RT/VPN" with LAN (your subnet) to VPN (the remote dial in user IP range, also your subnet)
Forum Administrator
Please Log in or Create an account to join the conversation.
- roga
- Topic Author
- Offline
- Junior Member
Less
More
- Posts: 17
- Thank yous received: 0
12 Aug 2019 09:34 #94856
by roga
Replied by roga on topic Re: Any idea how to restrict dial in users to one tcp protocol?
Thanks @admin3
I was thinking something similar my self, I'll give it a try and let you know how I get on
I was thinking something similar my self, I'll give it a try and let you know how I get on
Please Log in or Create an account to join the conversation.
- roga
- Topic Author
- Offline
- Junior Member
Less
More
- Posts: 17
- Thank yous received: 0
15 Aug 2019 11:01 #94865
by roga
Replied by roga on topic Re: Any idea how to restrict dial in users to one tcp protocol?
I got it going using a couple of filters: I set the dial in range as an object, then had a rule to block unless further matched, then had a rule to allow only port 3389 through to specific servers.
I would have uploaded some screen shots, but not so easy to do on this board.
Roga
I would have uploaded some screen shots, but not so easy to do on this board.
Roga
Please Log in or Create an account to join the conversation.
Moderators: Chris
Copyright © 2025 DrayTek