DrayTek UK Users' Community Forum
Help, Advice and Solutions from DrayTek Users
Block Outbound port 25 on Vigor 2600+
- its_epsom
- Topic Author
- Offline
- Junior Member
Less
More
- Posts: 12
- Thank you received: 0
05 May 2009 11:33 #55639
by its_epsom
Block Outbound port 25 on Vigor 2600+ was created by its_epsom
Hi, have a 2600+ running latest 2.5.9_UK firmware.
I'm trying to set-up a rule that will block all outbound traffic on port 25 but it just does not seem work! Any advise would be very much appreciated as I'm just going round in circles.... :?
Under the firewall general set-up the Data Filter is enabled and is set to start with filter set Set#2.
I have set-up a Filter Rule (number 2) under the default data filter of xNetBios -> DNS.
Check to enable The Filter Rule = CHECKED
Pass or Block = Block Immediately
Branch to Other Filter Set = None
Direction = OUT
Protocol = TCP
Source IP = any
Subnet Mask = 255.255.255.0 (/24)
Operator = "="
Start Port = 25
End Port = LEFT EMPTY
Dest IP = any
Subnet Mask = 255.255.255.0 (/24)
Operator = "="
Start Port = 25
End Port = LEFT EMPTY
Keep State = UNCHECKED
Fragments = Don't care
However I am still able to telnet to an external mailserver on port 25!!!
Thanks in advance!
(a very frustrated) Adam
I'm trying to set-up a rule that will block all outbound traffic on port 25 but it just does not seem work! Any advise would be very much appreciated as I'm just going round in circles.... :?
Under the firewall general set-up the Data Filter is enabled and is set to start with filter set Set#2.
I have set-up a Filter Rule (number 2) under the default data filter of xNetBios -> DNS.
Check to enable The Filter Rule = CHECKED
Pass or Block = Block Immediately
Branch to Other Filter Set = None
Direction = OUT
Protocol = TCP
Source IP = any
Subnet Mask = 255.255.255.0 (/24)
Operator = "="
Start Port = 25
End Port = LEFT EMPTY
Dest IP = any
Subnet Mask = 255.255.255.0 (/24)
Operator = "="
Start Port = 25
End Port = LEFT EMPTY
Keep State = UNCHECKED
Fragments = Don't care
However I am still able to telnet to an external mailserver on port 25!!!
Thanks in advance!
(a very frustrated) Adam
Please Log in or Create an account to join the conversation.
- louis-m
- Offline
- Member
Less
More
- Posts: 131
- Thank you received: 0
05 May 2009 12:04 #55641
by louis-m
2820 = 3.3.2_RC5
2950 = 3.2.4
Replied by louis-m on topic Block Outbound port 25 on Vigor 2600+
change:
source ip = your lan range
source port = 1024 - 65635
protocol = tcp
destination port = 25 - 25
protocl = tcp
your issue is with your source ports. they do not connect FROM 25 but from a range of 1024 and above.
eg 1024 > 25 or 1025 > 25 etc etc
*** be aware, you will block ALL communication to ALL mail servers with the above rule from anywhere on your lan ***
source ip = your lan range
source port = 1024 - 65635
protocol = tcp
destination port = 25 - 25
protocl = tcp
your issue is with your source ports. they do not connect FROM 25 but from a range of 1024 and above.
eg 1024 > 25 or 1025 > 25 etc etc
*** be aware, you will block ALL communication to ALL mail servers with the above rule from anywhere on your lan ***
2820 = 3.3.2_RC5
2950 = 3.2.4
Please Log in or Create an account to join the conversation.
- its_epsom
- Topic Author
- Offline
- Junior Member
Less
More
- Posts: 12
- Thank you received: 0
Moderators: Chris, Sami
Copyright © 2024 DrayTek