12.2.7 Creating or Deleting a Firewall Rule
A firewall is available for all connections via the LAN ext interface. It is used to
prevent unauthorized data traffic. The logic of the firewall states that any data
traffic is forbidden, which is not explicitly permitted through a rule. If you enable
the firewall for the connection type "Dial-Out", only connections will be possible
which are authorised by the firewall rules. All other connections will be blocked.
Due to the "stateful firewall" it is possible that changes to these
functions will not become effective immediately. This may happen if
connections or connection attempts have already been made.
Configuration via web interface (menu "LAN (ext)", page "Firewall")
In order to enable the firewall for IPv4 connections via the LAN ext
interface, check the checkbox "Activate firewall for LAN (ext) interface".
In order to enable the firewall for IPv6 connections via the LAN ext
interface, check the checkbox "Activate IPv6 firewall for LAN (ext)
interface".
It is strongly recommended to keep the firewall for IPv6 always
enabled, even if IPv6 is not used.
In order to create a rule for a permitted IP connection, proceed as
follows.
Select in the section "Allow new connection" in the drop-down list field
"Data direction" a data direction for the rule.
Define the protocol of the permitted connection in the drop-down list
field "Protocol".
Select the IP version for which the rule shall apply in the drop-down list
"IP version".
Enter the further specifications of the connections permitted by the
router into the entry fields "Source IP address", "Destination IP address"
and "Destination port". Only rules can be created, which are not valid for
individual machines (hosts), but for whole networks. In this case, the
netmask must be entered following the "/".
Save your settings by clicking "OK".
In order to temporarily disable firewall rules, uncheck in the section
"Allowed connections ..." the check box in the column "active" in the
firewall rule overview. Click on "OK" to confirm the settings.
In order to delete one or more rules, check the checkbox in the column
"delete" in the firewall rule overview. Click on "OK" to confirm the
settings.