DrayTek UK Users' Community Forum

Help, Advice and Solutions from DrayTek Users

2920n NAT feature: Restrict WAN Users by IP

  • silentreproach
  • Topic Author
  • Offline
  • New Member
  • New Member
More
22 Jun 2013 01:48 #76760 by silentreproach
2920n NAT feature: Restrict WAN Users by IP was created by silentreproach
We recently purchased 5 Vigor 2920n routers (spread around multiple offices) and one missing feature that is very important is to lock down incoming NAT by ip address. That is, some inbound ports need to be restricted to a specific WAN ip address or addresses.

For example, let's say we use NAT to allow incoming Remote Desktop port 3389 (again, just an example) and we want to restrict access so that only specific WAN ip addresses can connect on that port. Other routers, such as Netgear FVS338 allow the choice of either a single ip address, or range of ip addresses to have inbound access, per each defined port. Some routers even go so far as to allow a whilelist of ip addresses.

This would be awesome, please add this feature!

Dragging behind you the silent reproach of a million tear stained eyes. -Pink Floyd

Please Log in or Create an account to join the conversation.

More
22 Jun 2013 17:46 #76764 by voodle
That's not a missing feature imo, just use the firewall to achieve that.

Please Log in or Create an account to join the conversation.

  • silentreproach
  • Topic Author
  • Offline
  • New Member
  • New Member
More
26 Jun 2013 13:21 #76806 by silentreproach
Replied by silentreproach on topic Re: 2920n NAT feature: Restrict WAN Users by IP
How would you accomplish this with the firewall? I've looked at the interface and router manual, neither of which are terribly intuitive.

Dragging behind you the silent reproach of a million tear stained eyes. -Pink Floyd

Please Log in or Create an account to join the conversation.

  • silentreproach
  • Topic Author
  • Offline
  • New Member
  • New Member
More
22 Jul 2013 14:04 #77049 by silentreproach
Replied by silentreproach on topic Re: 2920n NAT feature: Restrict WAN Users by IP
Anyone know how to do this?

Dragging behind you the silent reproach of a million tear stained eyes. -Pink Floyd

Please Log in or Create an account to join the conversation.

More
23 Jul 2013 15:08 #77059 by voodle
here's a copy paste of an example:

If you have multiple IP addresses that you want to allow through the
firewall, you will need to go to Objects Setting then IP Objects,
click an index / link on there and add the IP address details (single
IP / subnet IP / range IP). You will need to do this for each IP
address that you want to allow if they are in separate IP ranges.
You can then add them to an IP Group under Objects Setting then IP
Group, select an index/link on there and add the IP Objects to the
group.

To configure the filter rules, go to the Firewall menu then Filter
Setup and on there go to #2 Default Data Filter and select the first
un-used filter rule:

Filter Rule #1:

Comment: Block SMTP
Direction: WAN to LAN
Source IP: leave this set to Any
Destination IP: leave this set to Any
Service Type: click Edit, select TCP, leave Source Port as 1-65535,
set Destination Port to 25-25, or create a Service Type
Object called SMTP with the same settings.
Action: Block if No Further Match

Filter Rule #2:

Comment: Allow SMTP
Direction: WAN to LAN
Source IP: click Edit and either specify the address you want to
allow, or set the Address Type to Group and Objects and select the IP
Group you created, then click OK.
Destination IP: leave this set to Any
Service Type: same as the previous rule
Action: Pass Immediately

That should then limit access to port 25 TCP to those IP addresses
only.

Please Log in or Create an account to join the conversation.

Moderators: Sami