Deny any outgoing traffic on WAN 25port except 1 fix IP.
Hello!
How can I set Gateway ACL to block outgoing SMTP traffic on the network (LAN, Wireless) expect the mail server with dedicated IP connected to gateways LAN port directly?
As first to understand the logic of ACL I am tried with IP-Port Group, to block any outgoing 25port, but without any success. I can send mail further on.
The next step should be to allow the the outgoing 25 port traffic only for an exact IP.
I have ER706W (router, WiFi, switch ) - EAP650 and EAP225outdoor connected with MESH (the last one is working as LAN bridge as well).
Thank you in advance!
N
- Copy Link
- Subscribe
- Bookmark
- Report Inappropriate Content
- Copy Link
- Report Inappropriate Content
ACL rules are read from top to bottom. So first you create allow rules then deny which is below the allow rule
here is an example of this
at the bottom I have blocked all private IPs, in the rule above I have allowed some private IPs, this is to block some remote LANs in site to site vpn
- Copy Link
- Report Inappropriate Content
Hello! Thanks for the reply!
I know that rules sequence is important. But currently I lost in the fist step, how to block any IP (lan, wifi) on the network using 25 port for WAN OUTgoing traffic.
More simple, deny any IoT, TV,Mobile,etc., to be able to send mails on network.
deny: out 192.168.1.xxx:25
If I will be convince that this block is working. I well give access only for dedicated mail server.
permit: out 192.168.1.111:25
NOTE: "in 192.168.1.xxx:25" could be open for any IP
Thanks!
- Copy Link
- Report Inappropriate Content
rule 1 allow port 25 from mail server
rule 2 block port 25 for all
and switch source and destination,
- Copy Link
- Report Inappropriate Content
- Copy Link
- Report Inappropriate Content
Hello, thanks for your help to figure it out.
I have changed the direction like above:
so:
Waited a minute and still can send mails...
What have I missed?
- Copy Link
- Report Inappropriate Content
- Copy Link
- Report Inappropriate Content
Based on your instruction I have successfully created my ACL rules, that working as is expected!
Thank you MR.s!
N
- Copy Link
- Report Inappropriate Content
Information
Helpful: 0
Views: 105
Replies: 7
Voters 0
No one has voted for it yet.