Firewall rule question

Currently reading
Firewall rule question

1,317
262
NAS
DS 718+, 2x-DS 720+
Router
  1. RT2600ac
Operating system
  1. Windows
Mobile operating system
  1. iOS
Last edited:
Regarding RT2600ac firewall:
Say the rule I want to make involves allowing (or denying) IP of 192.168.1.100, and Wan IP of 8.8.8.8 (for this discussion).

My question is: do I need to make 1 or 2 rules to cover both inbound and outbound directions?
One 192.168.1.100 to 8.8.8.8 to cover outbound

And one 8.8.8.8 to 192.168.1.100 to cover inbound

I’m not clear on this… to cover both directions, 1 or 2 rules?

Thank you
 
Firewall rules work on connections (sessions). The initial packet will determine the source IP and destination IP, after this the rule is applied to packets in both directions. You have to create the firewall rule for those source and destination IPs.

If the reverse connection initiation is to be handled then you'll have to create a second rule. So to answer your question: to stop outbound connections from the LAN device will be one rule (LAN IP as source) and to stop inbound connections to the LAN device is a second rule (LAN IP as destination). In the latter situation you could just not have a port forwarding (NAT) rule instead. Inbound to private IPs are blocked by default due to no NAT.

If this was a packet filter router then you'd have to create two rules per firewall rule anyway, as packet filters don't link packets into sessions.
 

Create an account or login to comment

You must be a member in order to leave a comment

Create account

Create an account on our community. It's easy!

Log in

Already have an account? Log in here.

Similar threads

Mr. T! You are Correct! I just learned this elsewhere!! Those IP’s Does unexpected things with pings and...
Replies
5
Views
1,524
I have setup from zero, thanks for trying to help. Thread can be closed now.
Replies
6
Views
1,973
Well, the one thing I didn't try...It didn't like the DS name, but just entering the IP address in the...
Replies
13
Views
5,169
It was but saw that I didn't need it. Thank you though. I know these rules are basic in comparison to...
Replies
4
Views
2,246
That's what I would do and then test it. Easiest is to use a mobile deivce. The NAT / port forwarding...
Replies
1
Views
2,528
All. One minute I can see where to post then I look away and its gone (ok down off the page under...
Replies
0
Views
461
OK. I don't bother with QuickConnect for my router, there's nothing running on it that others need to have...
Replies
6
Views
1,533

Welcome to SynoForum.com!

SynoForum.com is an unofficial Synology forum for NAS owners and enthusiasts.

Registration is free, easy and fast!

Trending threads

Back
Top