Deny any outgoing traffic on WAN 25port except 1 fix IP.

Deny any outgoing traffic on WAN 25port except 1 fix IP.

Deny any outgoing traffic on WAN 25port except 1 fix IP.
Deny any outgoing traffic on WAN 25port except 1 fix IP.
Monday - last edited Monday
Model: ER706W  
Hardware Version: V1
Firmware Version: 1.1.2

Hello!

 

How can I set Gateway ACL to block outgoing SMTP traffic on the network (LAN, Wireless) expect the mail server with dedicated IP connected to gateways LAN port directly?

As first to understand the logic of ACL I am tried with IP-Port Group, to block any outgoing 25port, but without any success. I can send mail further on.

The next step should be to allow the the outgoing 25 port traffic only for an exact IP.

I have ER706W (router, WiFi, switch ) - EAP650 and EAP225outdoor connected with MESH (the last one is working as LAN bridge as well).

 

Thank you in advance!

N

 

 

  0      
  0      
#1
Options
1 Accepted Solution
Re:Deny any outgoing traffic on WAN 25port except 1 fix IP.-Solution
Monday - last edited Monday

  @NovaMIT 

 

You have to creat an alow rule to.

 

 

 

IP Port group like this

 

 

Port group like this

 

 

Recommended Solution
  0  
  0  
#8
Options
7 Reply
Re:Deny any outgoing traffic on WAN 25port except 1 fix IP.
Monday

  @NovaMIT 

 

 

ACL rules are read from top to bottom. So first you create allow rules then deny which is below the allow rule

 

here is an example of this

at the bottom I have blocked all private IPs, in the rule above I have allowed some private IPs, this is to block some remote LANs in site to site vpn

 

  0  
  0  
#2
Options
Re:Deny any outgoing traffic on WAN 25port except 1 fix IP.
Monday

  @MR.S 

 

Hello! Thanks for the reply!

 

I know that rules sequence is important. But currently I lost in the fist step, how to block any IP (lan, wifi) on the network using 25 port for WAN OUTgoing traffic.

More simple, deny any IoT, TV,Mobile,etc., to be able to send mails on network.

 

deny: out 192.168.1.xxx:25

 

If I will be convince that this block is working. I well give access only for dedicated mail server.

permit: out 192.168.1.111:25

 

NOTE: "in 192.168.1.xxx:25" could be open for any IP

 

Thanks!

 

  0  
  0  
#3
Options
Re:Deny any outgoing traffic on WAN 25port except 1 fix IP.
Monday - last edited Monday

  @NovaMIT 

 

rule 1 allow port 25 from mail server
rule 2 block port 25 for all

 

and switch source and destination,

 

 

 

  0  
  0  
#4
Options
Re:Deny any outgoing traffic on WAN 25port except 1 fix IP.
Monday

  @NovaMIT 

 

This is how you should do it.

  0  
  0  
#6
Options
Re:Deny any outgoing traffic on WAN 25port except 1 fix IP.
Monday

  @MR.S 

 

Hello, thanks for your help to figure it out.

I have changed the direction like above:

so:

 

Waited a minute and still can send mails...

What have I missed?

  0  
  0  
#7
Options
Re:Deny any outgoing traffic on WAN 25port except 1 fix IP.-Solution
Monday - last edited Monday

  @NovaMIT 

 

You have to creat an alow rule to.

 

 

 

IP Port group like this

 

 

Port group like this

 

 

Recommended Solution
  0  
  0  
#8
Options
Re:Deny any outgoing traffic on WAN 25port except 1 fix IP.
Monday

  @MR.S

Based on your instruction I have successfully created my ACL rules, that working as is expected!

Thank you MR.s!

 

N

  0  
  0  
#9
Options