• March 28, 2024, 03:33:57 AM
  • Welcome, Guest
Please login or register.

Login with username, password and session length
Advanced search  

News:

This Forum Beta is ONLY for registered owners of D-Link products in the USA for which we have created boards at this time.

Author Topic: Need help with firewall rules  (Read 6420 times)

cheezy1963

  • Level 1 Member
  • *
  • Posts: 3
Need help with firewall rules
« on: December 28, 2017, 09:52:25 AM »

Dir-842
HW:B1
FW:2.02
Region:US

I have a NAS which I've setup as DMZ host and can access from WAN with no problems. Now I need help with Firewall rule to allow NAS on LAN to send email over port 587 but deny all other ports for NAS. Also need to deny all other LAN devices on any port to WAN.

Basically I need the NAS to be the only device on the LAN to be able to access the WAN (and only be able to send email on port 587). Hope this makes sense.

A little confused if I need to enable SPI IPv4 and choose to turn ON firewall and Allow rules and how to setup the rules while still allowing DMZ access to the NAS. If needed, I could remove the NAS from the DMZ.
Logged

FurryNutz

  • Poweruser
  •   ▲
    ▲ ▲
  • *****
  • Posts: 49923
  • D-Link Global Forum Moderator
    • Router Troubleshooting
Re: Need help with firewall rules
« Reply #1 on: December 28, 2017, 11:51:25 AM »

Link>Welcome!

Internet Service Provider and Modem Configurations
  • What ISP Service do you have? Cable or DSL?
  • What ISP Modem Mfr. and model # do you have?

When using the DMZ, the firewall and port configurations are not supported since the DMZ is wide open to the WAN side and nothing can't be configured when using the DMZ.

You might try removing the NAS from the DMZ and set up a Virtual Server and DNS Relay enabled configuration on the router and see if this helps better.
Here some resources to review:
http://forums.dlink.com/index.php?topic=13539.0
Difference between "Virtual Servers" and "Port Forwarding"
Logged
Cable: 1Gb/50Mb>NetGear CM1200>DIR-882>HP 24pt Gb Switch. COVR-1202/2202/3902,DIR-2660/80,3xDGL-4500s,DIR-LX1870,857,835,827,815,890L,880L,868L,836L,810L,685,657,3x655s,645,628,601,DNR-202L,DNS-345,DCS-933L,936L,960L and 8000LH.

cheezy1963

  • Level 1 Member
  • *
  • Posts: 3
Re: Need help with firewall rules
« Reply #2 on: December 28, 2017, 06:39:32 PM »

thanks for your response.

ISP is T-mobile on hotspot connected to another router.

I have removed the NAS from the DMZ. I can connect via wireless to the Dir-842 if I need to admin the NAS.

This leaves me with figuring out how to restrict the NAS to be the only device on the LAN to be able to access the WAN (and only be able to send email on port 587).

Do I need to enable SPI IPv4?

I've tried the following without any luck. Mail stops working and other devices on the LAN are allowed to WAN. I must be missing something.

-->IPv4 rules
Turn IPv4 filtering On and allow rules listed

created Only one Rule...
Name:enable_mail
Source address range: LAN 10.0.0.1 {NAS address}
Dest address range: WAN 0.0.0.0-255.255.255.255
Port range: TCP 587
Schedule: Always enable
Logged

FurryNutz

  • Poweruser
  •   ▲
    ▲ ▲
  • *****
  • Posts: 49923
  • D-Link Global Forum Moderator
    • Router Troubleshooting
Re: Need help with firewall rules
« Reply #3 on: December 29, 2017, 09:48:27 AM »

"ISP is T-mobile on hotspot connected to another router."
Whats this other router? Having two routers on the same line will effect how this all works.
Logged
Cable: 1Gb/50Mb>NetGear CM1200>DIR-882>HP 24pt Gb Switch. COVR-1202/2202/3902,DIR-2660/80,3xDGL-4500s,DIR-LX1870,857,835,827,815,890L,880L,868L,836L,810L,685,657,3x655s,645,628,601,DNR-202L,DNS-345,DCS-933L,936L,960L and 8000LH.

cheezy1963

  • Level 1 Member
  • *
  • Posts: 3
Re: Need help with firewall rules
« Reply #4 on: December 29, 2017, 09:54:20 PM »

I think I understand what you are saying but I don't see how it matters since I'm trying to only control WAN/outbound access on the DIR-842.

Here is my setup:

Internet(T-Mobile hotspot)-->AirLink101-->Dir-842-->NAS (and other wireless devices)

I get email from the NAS when no firewall rules are enabled on the Dir-842 and the wireless devices can access the internet.
WHen I attempt to setup firewall rules on the DIR-842,I stop getting emails from the NAS.

How can I restrict the NAS to be the only device on the LAN side of the DIR-842 to be able to access the WAN side (and only be able to send email on port on port 587).

Can you help me with what the rule or rules and what to enable/disable?
Logged

FurryNutz

  • Poweruser
  •   ▲
    ▲ ▲
  • *****
  • Posts: 49923
  • D-Link Global Forum Moderator
    • Router Troubleshooting
Re: Need help with firewall rules
« Reply #5 on: March 13, 2018, 02:34:22 PM »

Any updates on this?

 ???
Logged
Cable: 1Gb/50Mb>NetGear CM1200>DIR-882>HP 24pt Gb Switch. COVR-1202/2202/3902,DIR-2660/80,3xDGL-4500s,DIR-LX1870,857,835,827,815,890L,880L,868L,836L,810L,685,657,3x655s,645,628,601,DNR-202L,DNS-345,DCS-933L,936L,960L and 8000LH.