Draytek 2820 firewall setup

Associate
Joined
22 Nov 2007
Posts
1,696
Location
Staffordshire
I'm trying to configure a Draytek 2820 firewall to only allow certain external IP addresses to access certain ports on a server on the internal network.

I've set the port forwarding up and at the moment it lets anyone to connect. I've tried to setup the firewall up, but not having much luck. I've done the following:

Created a new filter set.
Rule 1:
Direction: WAN->LAN
Source IP: IP Object containing the list of IP addresses.
Destination: Internal IP address of server.
Service Type: Object group with the list of ports I need.
Filter: Pass Immediately.

Rule 2:
Direction: WAN->LAN
Source IP: Any
Destination: Internal IP address of server.
Service Type: Object group with the list of ports I need.
Filter: Block Immediately.

With the current setup, its allowing any external address to connect to the server. Where am I going wrong?
 
Last edited:
Ok, I started from scratch and set up five rules.

Rule 1:
Direction: WAN->LAN
Source IP: External IP address I want to access the server
Destination: Internal IP address of server.
Service Type: Object group with the list of ports I need.
Filter: Pass Immediately.

Rule 2:
Direction: WAN->LAN
Source IP: External IP address I want to access the server
Destination: Internal IP address of server.
Service Type: Object group with the list of ports I need.
Filter: Pass Immediately.

Rule 3:
Direction: WAN->LAN
Source IP: External IP address I want to access the server
Destination: Internal IP address of server.
Service Type: Object group with the list of ports I need.
Filter: Pass Immediately.

Rule 4:
Direction: WAN->LAN
Source IP: External IP address I want to access the server
Destination: Internal IP address of server.
Service Type: Object group with the list of ports I need.
Filter: Pass Immediately.

Rule 5:
Direction: WAN->LAN
Source IP: Any
Destination: Internal IP address of server.
Service Type: Any
Filter: Block if no further match

With that setup it stops all external IP address from accessing the server even the ones I specified in rules 1-4. Any ideas?
 
Back
Top Bottom