- 2,663
- 509
- NAS
- DS 718+, 2x-DS 720+
- Router
- RT2600ac
- Operating system
- Windows
- Mobile operating system
- iOS
Last edited:
No VLAN here, due to the amount of TP self created Rules created YEARS AGO.... These All would Need IP editing if a VLAN was used)...A year or so ago (Probably longer), I added a bunch of firewall rules to break out the "HITS" so more explicitly explain where the "Hits" are coming from....
At that time I also created rules for ICMP (PINGS), too... This was augmented by creating and using a: BOGUS GATEWAY, for devices I don't want to ever access internet, and followed up with Router Firewall Rules tto verify that devices using "Bogus Gateway" did not try to use "Real Gateway" later!!!
One year later, I am more or less happy with the Rules I created, but the HITS are kind of vague...as there are some Un-Known hits from IP's..... and less ICMP rules than TCP/UDP rules getting hits... So If an issue came up with a device going rouge or such, It would be hard to determine which device was acting up.... That is the basis of this.... Nothing acting up now, but wanting to make it easier to determine if a device went rouge in the future!!!!
I'm thinking it would be easier to determine ICMP than TCP/UDP, so I'm starting there.. ICMP, as it will cause less issues if I do something stupid...
For example, today I see 82 Pings HITS, from devices that are NOT Security cameras, nor Computers, or NAS’s…. on my BLOCK ALL IP's with ICMP...
Due to the way I've separated my IP Groups years ago, I see his will cause more rules than I hoped for.... to cover the 256 devices that could be on my LAN...
Obviously, I should 'start over' with new ranges for all devices on the LAN, to simplify the IP range's being used, but that puts me back where I was with VLAN in that I have hundreds of TP Self Created rules I'd have to edit... So AGAIN I'm leaving the EXISTING IP's alone.... and continuing on with multiple Firewall ICMP Rules....
My original idea for revised ICMP Rules were 11 rules, but got it down to 3 plus the existing 3 ICMP rules...
Turns out my existing TCP/UDP allow rules had done about 90% of this already, but under vaguely named rules over the years... Updated Rule names to more aptly explain what's going on it them! I could add a few more to break the HITs down to more specific devices... So I did. That's What I get for creating firewall rules with vague names over a 5+ year time frame!! This made things clearer, too.
What this will result in: The ICMP DENY ALL rule should go to ZERO HITS, and the TCP/UDP Allow rules will break out Hits to a more explain-able list.... Making subsequent troubleshooting (should a device start acting bad, in the future)..... Easier to spot!
ICMP Deny and Allow rules are now finished.... TCP/UDP Allow Rules are finished. Deny breakout is mostly done, but is covered by the DENY ALL rule at bottom of firewall list. And my Firewall Rules have been Renamed in a way to make them clearer in name as to what they are doing!
Would have liked to do his on FIrewall on NAS's too... but not seeing "HITS" makes it hard to create specific rules, even if you wanted to!!! This also makes rules created that should NEVER see a HIT impossible - on NAS's.... Oh! How I wish NAS's Firewall Had HITS!!!!
At that time I also created rules for ICMP (PINGS), too... This was augmented by creating and using a: BOGUS GATEWAY, for devices I don't want to ever access internet, and followed up with Router Firewall Rules tto verify that devices using "Bogus Gateway" did not try to use "Real Gateway" later!!!
One year later, I am more or less happy with the Rules I created, but the HITS are kind of vague...as there are some Un-Known hits from IP's..... and less ICMP rules than TCP/UDP rules getting hits... So If an issue came up with a device going rouge or such, It would be hard to determine which device was acting up.... That is the basis of this.... Nothing acting up now, but wanting to make it easier to determine if a device went rouge in the future!!!!
I'm thinking it would be easier to determine ICMP than TCP/UDP, so I'm starting there.. ICMP, as it will cause less issues if I do something stupid...
For example, today I see 82 Pings HITS, from devices that are NOT Security cameras, nor Computers, or NAS’s…. on my BLOCK ALL IP's with ICMP...
Due to the way I've separated my IP Groups years ago, I see his will cause more rules than I hoped for.... to cover the 256 devices that could be on my LAN...
Obviously, I should 'start over' with new ranges for all devices on the LAN, to simplify the IP range's being used, but that puts me back where I was with VLAN in that I have hundreds of TP Self Created rules I'd have to edit... So AGAIN I'm leaving the EXISTING IP's alone.... and continuing on with multiple Firewall ICMP Rules....
My original idea for revised ICMP Rules were 11 rules, but got it down to 3 plus the existing 3 ICMP rules...
Turns out my existing TCP/UDP allow rules had done about 90% of this already, but under vaguely named rules over the years... Updated Rule names to more aptly explain what's going on it them! I could add a few more to break the HITs down to more specific devices... So I did. That's What I get for creating firewall rules with vague names over a 5+ year time frame!! This made things clearer, too.
What this will result in: The ICMP DENY ALL rule should go to ZERO HITS, and the TCP/UDP Allow rules will break out Hits to a more explain-able list.... Making subsequent troubleshooting (should a device start acting bad, in the future)..... Easier to spot!
ICMP Deny and Allow rules are now finished.... TCP/UDP Allow Rules are finished. Deny breakout is mostly done, but is covered by the DENY ALL rule at bottom of firewall list. And my Firewall Rules have been Renamed in a way to make them clearer in name as to what they are doing!
Would have liked to do his on FIrewall on NAS's too... but not seeing "HITS" makes it hard to create specific rules, even if you wanted to!!! This also makes rules created that should NEVER see a HIT impossible - on NAS's.... Oh! How I wish NAS's Firewall Had HITS!!!!