D-Link Forums

The Graveyard - Products No Longer Supported => Routers / COVR => DIR-655 => Topic started by: leshric on March 27, 2014, 11:38:40 AM

Title: How to block traffic on a port except from one external server?
Post by: leshric on March 27, 2014, 11:38:40 AM
I have a VOIP phone system and my phones are getting random unanswerable calls.  My provider says that this is because random people are probing my IP port 5060 which is causing the phones to ring.  They say that I just need to block all incoming traffic on port 5060 except from their server, but I can't figure out how to do it!  Can this router do that or do I need a new one?

I have a DIR-655 Rev A, FW 1.35NA

Thanks!
Title: Re: How to block traffic on a port except from one external server?
Post by: FurryNutz on March 27, 2014, 11:46:55 AM
Link>Welcome! (http://forums.dlink.com/index.php?topic=48135.0)



Internet Service Provider and Modem Configurations

You'll need to set up scheduling and access control to block this specific port. It's been a while however under access control there is a setting that you can input a specific custom port number to block.

Found it, under Advanced/Access Control, Step 4: Select Block Some Access, and check mark Apply Advanced Port Filters, select Next and then you see the display to input port numbers and input a range of IP addresses to filter for that port number. I recommend gathering all effected devices and reserving the IP addresses first for each phone. Start at 192.168.0.100 and assign them sequentially up to the ending IP address for the last one.

So when you have done this, you'll see the Dest IP Start and End range. Just input 192.168.0.100 and the last IP address for the last phone in to the Dest IP End range. Input the port number for both Dest Start and End and select any Protocol.

Select Save. Reboot the router and test.
Title: Re: How to block traffic on a port except from one external server?
Post by: FurryNutz on May 05, 2014, 07:33:33 AM
Any status on this?  ???

I have a VOIP phone system and my phones are getting random unanswerable calls.  My provider says that this is because random people are probing my IP port 5060 which is causing the phones to ring.  They say that I just need to block all incoming traffic on port 5060 except from their server, but I can't figure out how to do it!  Can this router do that or do I need a new one?

I have a DIR-655 Rev A, FW 1.35NA

Thanks!
Title: Re: How to block traffic on a port except from one external server?
Post by: PacketTracer on August 31, 2014, 03:31:37 PM
Hi Furry,

reading what you wrote I'm in doubt if this is what the OP wants: Configuring ACCESS CONTROL means to restrict selected local clients to use specific destinations in the Internet.

But here it is the other way round: The OP wants to restrict connections coming from the Internet to connect to port 5060 of his local phone system except for connection requests coming from a specific server IP address of his provider!

And to my mind the solution could be a combination of

In detail:

[1] Define Inbound Filter "Provider":

       - Check the Enable check box
        - Enter Remote IP Start = <IP address of provider's server>
        - Enter Remote IP End = <IP address of provider's server>

[2] Define a Virtual Server:


Probably the OP already has some kind of Virtual Server or Port Forwarding rule for port 5060 because otherwise it couldn't have happened what he describes. And probably within the corresponding rule he has set the Inbound Filter to "Allow All". If so, all he has to do is step [1] and then change the Inbound Filter from "Allow All" to "Provider".

PT
Title: Re: How to block traffic on a port except from one external server?
Post by: FurryNutz on August 31, 2014, 03:33:50 PM
Awesome, I think the mis understood the external vs internal. Thanks PT.  ;)