DrayTek UK Users' Community Forum
Help, Advice and Solutions from DrayTek Users
Vigor 2960 Firewall Default
- ber18578
- Topic Author
- Offline
- New Member
Less
More
- Posts: 5
- Thank you received: 0
30 Mar 2021 14:38 #98968
by ber18578
Vigor 2960 Firewall Default was created by ber18578
Hello,
at the risk of exposing myself as a complete ignorant. What is the routers firewall doing to traffic from outside the internet if no rules are configured?
Regards
Bernhard
at the risk of exposing myself as a complete ignorant. What is the routers firewall doing to traffic from outside the internet if no rules are configured?
Regards
Bernhard
Please Log in or Create an account to join the conversation.
- ber18578
- Topic Author
- Offline
- New Member
Less
More
- Posts: 5
- Thank you received: 0
30 Mar 2021 16:37 #98971
by ber18578
Replied by ber18578 on topic Re: Vigor 2960 Firewall Default
To better specify, is Stateful Packet Inspection active per default or does it need a particular rule for activation?
Please Log in or Create an account to join the conversation.
- hornbyp
- Offline
- Big Contributor
Less
More
- Posts: 1323
- Thank you received: 0
31 Mar 2021 01:18 #98974
by hornbyp
Yes, it is (active).
In any case, the only "Open Ports" (ie in the NAT translation table), will be those that the Router had to 'open' in order to pass outbound traffic to the Internet. (Assuming of course, that Ports haven't been opened manually, Ports haven't been 'redirected' and no 'DMZ' host specified). So even with no firewall rules, there is very little/no? scope for unsolicited traffic to travel inbound.
Replied by hornbyp on topic Re: Vigor 2960 Firewall Default
Ber18578 wrote:
To better specify, is Stateful Packet Inspection active per default or does it need a particular rule for activation?
Yes, it is (active).
In any case, the only "Open Ports" (ie in the NAT translation table), will be those that the Router had to 'open' in order to pass outbound traffic to the Internet. (Assuming of course, that Ports haven't been opened manually, Ports haven't been 'redirected' and no 'DMZ' host specified). So even with no firewall rules, there is very little/no? scope for unsolicited traffic to travel inbound.
Please Log in or Create an account to join the conversation.
- ber18578
- Topic Author
- Offline
- New Member
Less
More
- Posts: 5
- Thank you received: 0
31 Mar 2021 07:54 #98976
by ber18578
Replied by ber18578 on topic Re: Vigor 2960 Firewall Default
Thanks for the help,
does this apply to IPv6 traffic as well?
does this apply to IPv6 traffic as well?
Please Log in or Create an account to join the conversation.
- piste basher
- Offline
- Big Contributor
Less
More
- Posts: 1193
- Thank you received: 7
31 Mar 2021 09:42 #98978
by piste basher
Replied by piste basher on topic Re: Vigor 2960 Firewall Default
I'm fairly sure that the "Block routing connections initiated from WAN" box for IPv6 is ticked by default. If it isn't suggest that you tick it....
Please Log in or Create an account to join the conversation.
- ber18578
- Topic Author
- Offline
- New Member
Less
More
- Posts: 5
- Thank you received: 0
31 Mar 2021 10:24 #98981
by ber18578
Replied by ber18578 on topic Re: Vigor 2960 Firewall Default
The Vigor2960 is a Linux based router so its configuartion interface doesn't have the tick box you are referring to. So thats why I was asking what happens if no Rules are defined, The default policy is "accept", that is why I was fearing that SPI on IPv6 traffic needs extra activation, although I couldn't find any means for enable/disable.
I want to setup IPv6 for a particular server for VoIP. i.e. one specific pass rule for this prefix on port 5060.
So that's why I was wondering if I can safely turn on IPv6 since I have active stateful packet inspection on IPv6 traffic.
I want to setup IPv6 for a particular server for VoIP. i.e. one specific pass rule for this prefix on port 5060.
So that's why I was wondering if I can safely turn on IPv6 since I have active stateful packet inspection on IPv6 traffic.
Please Log in or Create an account to join the conversation.
Moderators: Chris, Sami
Copyright © 2024 DrayTek