Prevent router from comunicating with the Internet

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.

Prevent router from comunicating with the Internet

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.
Prevent router from comunicating with the Internet
Prevent router from comunicating with the Internet
2024-03-01 18:53:58
Model: ER605 (TL-R605)  
Hardware Version: V2
Firmware Version:

Does the firewall of this router offer functionality similar to the INPUT/OUTPUT chains of iptables?

  0      
  0      
#1
Options
5 Reply
Re:Prevent router from comunicating with the Internet
2024-03-01 20:44:22

  @Bimo 

 

I'm 99% certain the router is using iptables internally.  How much of its functionality is exposed is another matter. 

 

Perhaps we start with what you want to do, and try to map it to UI functionality, because you will not be directly editing iptables conf files :)

<< Paying it forward, one juicy problem at a time... >>
  0  
  0  
#2
Options
Re:Prevent router from comunicating with the Internet
2024-03-02 01:45:39 - last edited 2024-03-02 01:49:00

  @d0ugmac1 I don't want the router to originate connections to the internet on its own. Like reaching for updates, asking for the time or due to bugs. Call me "old school" but i want the firewall to be completely mute to the internet. If updates are gonna be installed, I prefer to give them to the router from the lan. Nowadays, even popular Linux firewall distros are generating various connection request to the internet per one single user connection request. It reveals there is a firewall there and it reveals the model of the firewall too.

AFAIK in some companies, they have their own internal time and update servers that provide updates and time from behind the walls. These servers are connecting the internet only occasionally, from only one public IP, reducing this way the attack surface.

  0  
  0  
#3
Options
Re:Prevent router from comunicating with the Internet
2024-03-02 16:10:35

  @Bimo 

 

I'm not sure Omada is the router tech of choice for you then. 

 

That said, there's a pretty big sub-culture around here using Pfsense router boxes with Omada-controlled switches and APs though.

<< Paying it forward, one juicy problem at a time... >>
  0  
  0  
#4
Options
Re:Prevent router from comunicating with the Internet
2024-03-02 18:16:41

  @d0ugmac1 I really don't want to mention other brands here. First i wrote a long rant, then deleted it. Considering the alternatives, I still think R605 is the best deal. Will use it and rant to myself :)

  0  
  0  
#5
Options
Re:Prevent router from comunicating with the Internet
2024-03-04 01:48:55

Hi @Bimo 

Thanks for posting in our business forum.

Bimo wrote

Does the firewall of this router offer functionality similar to the INPUT/OUTPUT chains of iptables?

No. There is no way to configure CLI within tables.

ACL might be what you need.

 

ACL does not support IP-port yet. Which means you need to use IP for now. Block SRC to DST. SRC = LAN, DST = ALL IP.

Best Regards! If you are new to the forum, please read: Howto - A Guide to Use Forum Effectively. Read Before You Post. Look for a model? Search your model NOW Official and Beta firmware. NEW features! Subscribe for the latest update!Download Beta Here☚ ☛ ★ Configuration Guide ★ ☚ ☛ ★ Knowledge Base ★ ☚ ☛ ★ Troubleshooting ★ ☚ ● Be kind and nice. ● Stay on the topic. ● Post details. ● Search first. ● Please don't take it for granted. ● No email confidentiality should be violated. ● S/N, MAC, and your true public IP should be mosaiced.
  0  
  0  
#6
Options