DrayTek UK Users' Community Forum
Help, Advice and Solutions from DrayTek Users
2862 Firewall & VPN traffic
- davidmatthewson
- Topic Author
- Offline
- Junior Member
Less
More
- Posts: 27
- Thank you received: 0
14 Feb 2021 13:14 #98463
by davidmatthewson
2862 Firewall & VPN traffic was created by davidmatthewson
I wonder if anyone knows the answer to this pls?
We have a number of 2862 outers which are also end points for VPN traffic, both 'dial in' and LAN to LAN. They are being repeatedly attacked by some hacker who tries to make a L2P VPN connections on every end point many times a minute - and fails. The attacks all come from the same IP and I want to block this from even hitting the VPN endpoint. But when I try to set an IP 'Block Immediately' filter nothing seems to happen. So does the firewall logically sit in front of or behind the VPN end point logic in the 2862.
Any ideas on how to block this would be much appreciated.
TiA
We have a number of 2862 outers which are also end points for VPN traffic, both 'dial in' and LAN to LAN. They are being repeatedly attacked by some hacker who tries to make a L2P VPN connections on every end point many times a minute - and fails. The attacks all come from the same IP and I want to block this from even hitting the VPN endpoint. But when I try to set an IP 'Block Immediately' filter nothing seems to happen. So does the firewall logically sit in front of or behind the VPN end point logic in the 2862.
Any ideas on how to block this would be much appreciated.
TiA
Please Log in or Create an account to join the conversation.
- hornbyp
- Offline
- Big Contributor
Less
More
- Posts: 1323
- Thank you received: 0
14 Feb 2021 17:41 #98473
by hornbyp
Behind
Somewhere there is a Draytek support article detailing this scenario. It says to add the offending IP address to the "Black List" at Firewall >> Defense Setup
UPDATE: See:
https://www.draytek.com/support/knowledge-base/5982
Replied by hornbyp on topic Re: 2862 Firewall & VPN traffic
davidmatthewson wrote:
But when I try to set an IP 'Block Immediately' filter nothing seems to happen. So does the firewall logically sit in front of or behind the VPN end point logic in the 2862.
Any ideas on how to block this would be much appreciated.
Behind
Somewhere
UPDATE: See:
Please Log in or Create an account to join the conversation.
- davidmatthewson
- Topic Author
- Offline
- Junior Member
Less
More
- Posts: 27
- Thank you received: 0
14 Feb 2021 17:48 #98474
by davidmatthewson
Replied by davidmatthewson on topic Re: 2862 Firewall & VPN traffic
Excellent. Many thanks for this. I'll try it and revert with what happens.
Edited later:
Yes, this indeed seems to work. Of course,not along term solution as the scum will just come back with a different IP (range) but works well at present, so many thanks!
Edited later:
Yes, this indeed seems to work. Of course,not along term solution as the scum will just come back with a different IP (range) but works well at present, so many thanks!
Please Log in or Create an account to join the conversation.
Moderators: Chris, Sami
Copyright © 2024 DrayTek