UsingtheRouter’sWebInterface 22
Settingupfirewalls

Definingfirewallrules

Therouter'sfirewallenforcesasetofrulesthatdeterminehowincomingandoutgoingpacketsarehandled.
Bydefault,alloutboundtrafficoriginatingfromtheLANisallowedtopassthroughthefirewall,andall
inboundtrafficoriginatingfromexternalnetworksisdropped.Thiseffectivelycreatesaprotectivebarrier
betweentheLANandallothernetworks.

Addingforwardingrules

ForadevicewithintheLANtobevisiblefromtheinternetorfromanoutsidenetwork,createaforwarding
ruletoallowincomingpacketstoreachthedevice.
1. InthePortForwardinggroup,clickAddRule.
2. Enteranameanddescription.ClickNext.
3. IntheIPForwardingDNATpane,enterthefollowing:
IntheExternalWANPortsfield,typetheport(s)tobeforwarded.Commonportsarelistedinthe
field'sattacheddropdownlistandareexposedonceyouenteracharacter.TypeANYtoforwardall
ports.
IntheDestinationLANIPfield,typetheIPaddressofthedevicepacketswillbeforwardedto.The
attacheddropdownlistcontainsDHCPleasedandSavedNetworkaddresses.
IntheDestinationLANPortsfield,typetheporttowhichpacketsaretranslated.Ifthereisarangeof
ports,theendingportisautomaticallyset.TheDestinationLANendingportisbasedonthe
DestinationLANstartingportandtherangeprovidedintheExternalWANPort(s)field.
FromtheProtocoldropdownlist,selecttheprotocolofthemessagesthatcanbeforwarded.
Adefaultfilterallowingforwardedpacketsthroughthefirewallisautomaticallycreated.Ifdesired
youcanusetheAdvancedSettingmodeofthePortForwardingwizardtofurtherrestrictpackets
basedonsourceaddressandsourceports.Inmostcasesthisisnotnecessary.
4. ClickFinish.

AddingOutboundTrafficRules

TopreventadevicewithintheLANfromcommunicatingwithadeviceinanexternalnetwork,arulehastobe
establishedinthefirewalltodroppacketsdestinedtotheexternaldevice.
1. ClickAddRuleintheOutboundTrafficsection.
2. Enteranameanddescription.ClickNext.
3. IntheDestinationIPfield,typetheIPaddressofthedeviceornetworkpacketsarebeingsentto.Type
ANYifthedestinationaddressdoesnotmatter.
4. IntheDestinationMaskfield,typethenetworkmaskofthedestinationnetwork.
5. IntheDestinationPortfield,typetheportpacketsaredestinedfor.Commondestinationportsare
listedintheDestinationPortfield'sattacheddropdownlist.TypeANYifthedestinationportdoesnot
matter.
6. IntheSourceIPfield,typetheIPaddressofthedeviceornetworkthatthetrafficoriginatesfrom.Type
ANYifthesourceaddressdoesnotmatter.
7. IntheSourceMaskfield,typeanetworkmaskfortheoriginofthetraffic.