Technical Discussion
  >> DSL Hardware Discussion


Register (or login) on our website and you will not see this ad.


Pages in this thread: 1 | [2] | 3 | (show all)   Print Thread
Standard User caffn8me
(knowledge is power) Wed 19-Mar-14 00:29:11
Print Post

Re: DrayTek 2760n firewall


[re: deleted] [link to this post]
 
Excellent smile

I haven't got nmap running yet. It seems not to like Mavericks and my laptop is in another room.

Sarah

--
If I can't drink my bowl of coffee three times daily, then in my torment, I will shrivel up like a piece of roast goat

Spiders on coffee - Badass spiders on drugs
Standard User deleted
(deleted) Wed 19-Mar-14 00:31:12
Print Post

Re: DrayTek 2760n firewall


[re: caffn8me] [link to this post]
 
It was too good to be true. Somehow that again blocked outgoing traffic, but only with new connections. Chrome still worked, but other applications did not. Disabled DoS and they started working again.

I'm still at square one. I do have the remote management disabled I believe.
Standard User caffn8me
(knowledge is power) Wed 19-Mar-14 00:42:25
Print Post

Re: DrayTek 2760n firewall


[re: deleted] [link to this post]
 
One of the limitations of the Draytek firewall is that it doesn't allow blocking traffic to the WAN from outside the WAN in the rule sets.

I'll scan later tonight and let you know which ports I can see on mine.

Sarah

--
If I can't drink my bowl of coffee three times daily, then in my torment, I will shrivel up like a piece of roast goat

Spiders on coffee - Badass spiders on drugs


Register (or login) on our website and you will not see this ad.

Standard User deleted
(deleted) Wed 19-Mar-14 00:46:06
Print Post

Re: DrayTek 2760n firewall


[re: caffn8me] [link to this post]
 
So what I'm trying to achieve (and have done so on every other brand of router) can't be done on DrayTeks?

Odd definition of a firewall.
Standard User caffn8me
(knowledge is power) Wed 19-Mar-14 01:04:03
Print Post

Re: DrayTek 2760n firewall


[re: deleted] [link to this post]
 
I haven't found a way of blocking specific external IP addresses from accessing the WAN interface - any or all ports.

You also can't disable Telnet, FTP, SSH, HTTP and HTTPS administrative access to the router from internal LAN clients by disabling those protocols or firewall policies. If, for example, you have a staff LAN/VLAN and an admin LAN/VLAN and only want computers on the admin network to be able to access the admin pages of the router you're stuffed.

Another bug which irks me is that when you add local admin users they log into the router using their own name and password but the syslog only logs "admin" as the user. You also can't rename the default admin account.

I'm still getting to grips with a few things!

On the whole, I'm very pleased with the Drayteks but there are a few things which haven't been thought through.

Sarah

--
If I can't drink my bowl of coffee three times daily, then in my torment, I will shrivel up like a piece of roast goat

Spiders on coffee - Badass spiders on drugs

Edited by caffn8me (Wed 19-Mar-14 01:05:49)

Standard User deleted
(deleted) Wed 19-Mar-14 01:10:50
Print Post

Re: DrayTek 2760n firewall


[re: caffn8me] [link to this post]
 
They aren't the easiest interfaces I've found. I got it for my upcoming fibre install and I'm not one to use ISP provided hardware.

On previous routers, everything was filtered unless I specifically opened a port, so to have it the other way around is a little disconcerting, especially considering if I have UPnP enabled that shows as open. This was never the case on others.

I'll just work with NAT as that will offer some protection.

Thanks anyway.
Standard User caffn8me
(knowledge is power) Wed 19-Mar-14 01:18:27
Print Post

Re: DrayTek 2760n firewall


[re: deleted] [link to this post]
 
At least you'll be able to use the router without an external modem for fibre smile

Sarah

--
If I can't drink my bowl of coffee three times daily, then in my torment, I will shrivel up like a piece of roast goat

Spiders on coffee - Badass spiders on drugs
Standard User deleted
(deleted) Wed 19-Mar-14 03:54:30
Print Post

Re: DrayTek 2760n firewall


[re: deleted] [link to this post]
 
If helps

http://www.draytek.com/index.php?option=com_k2&view=...
http://www.draytek.com/index.php?option=com_k2&view=...
Standard User caffn8me
(knowledge is power) Wed 19-Mar-14 07:37:16
Print Post

Re: DrayTek 2760n firewall


[re: deleted] [link to this post]
 
Thank you, restricting by MAC address looks as if it will help but I'll have to test it and see if it works as the 2850 and 2860 are somewhat different.

Sarah

--
If I can't drink my bowl of coffee three times daily, then in my torment, I will shrivel up like a piece of roast goat

Spiders on coffee - Badass spiders on drugs
Standard User deleted
(deleted) Wed 19-Mar-14 11:10:49
Print Post

Re: DrayTek 2760n firewall


[re: deleted] [link to this post]
 
Thanks. These seem to be just blocking LAN clients from the router administration. I gave these two a try anyway and ports are still not filtered.

I understand that there is NAT protection, but it is not a firewall.
Pages in this thread: 1 | [2] | 3 | (show all)   Print Thread

Jump to