New here - Looking for ability to do whitelist blocking based on remote IP+destination IP and Port

New here - Looking for ability to do whitelist blocking based on remote IP+destination IP and Port

New here - Looking for ability to do whitelist blocking based on remote IP+destination IP and Port
New here - Looking for ability to do whitelist blocking based on remote IP+destination IP and Port
Sunday - last edited 12 hours ago

Hi,

 

I am new here and hopefully this is the correct place to post this... If not please point me to the correct place :)!

 

I work mostly remotely, and I have a small development environment here, but I also work with several other team members (who are also remote), and occasionally, I need to give them some limited access to some of the machines in my dev environment, e.g., for testing or working sessions.

 

The networking environment I have consists of a main router that connects to the ISP, and then I have a mesh network and the dev machines are hard wired on the mesh network, and while I was checking the logs in the mesh network, I am seeing occasional connections from outside IP addresses to ports on one of my dev machines, which is hosting a web server.

 

Unfortunately, neither the ISP (Verizon) router nor the mesh network are able to prevent those connections, so I have tried to block the connections on that web server machine, which is a Windows machine (so using Windows Defender firewall), but I'd really like to incorporate something to my environent that would me allow me to control the access, and I was chatting with one of my colleagues and he suggested that maybe an Omada router might be able to do what I am looking for?

 

Basically, what I think I need is "some network device" that can do whitelists blocking, based on the remote IP and the destination IP and port.

 

I am thinking that I could add that device between the ISP router and the mesh network, and then I could configure the blocking rules/whitelists that I need on that device.

 

I am posting here to inquire if this is something that can be done with any Omada device, and if so can you all recomment which device?

 

Thanks,

Jim

  0      
  0      
#1
Options
1 Accepted Solution
Re:New here - Looking for ability to do whitelist blocking based on remote IP+destination IP and Port-Solution
Monday - last edited 12 hours ago

Hi @ohaya1001 

Thanks for posting in our business forum.

ohaya1001 wrote

  @Clive_A 

 

Thanks for responding.  Can you clarify?  Would the Omada router be able to block incoming connections based on remote IP, and target IP and port?

 

FYI, my son, who works in networking (but not with Omada equipment) suggested:

 

https://www.amazon.com/dp/B0DDRC1T34

https://www.amazon.com/dp/B07GX6GVB6

 

Would that be able to block all incoming connections, other than the whitelisted one?

 

Thanks,

Jim

It is not perfect yet to specify the IP and Port like the Openwrt which you have many options and ways to achieve what you described.

It now has a limitation in Controller mode where you cannot specify the IP-Port Group in the directions.

 

For other aspects, see this:

ACL Guide Compilation

What worries me is that it might not be what you are after. So to avoid that, you can see the common implementation of this router.

Emulator of the controller: https://support.omadanetworks.com/en/product/omada-software-controller/v5/?resourceType=tool

Best Regards! If you are new to the forum, please read: Howto - A Guide to Use Forum Effectively. Read Before You Post. Look for a model? Search your model NOW Official and Beta firmware. NEW features! Subscribe for the latest update!Download Beta Here☚ ☛ ★ Configuration Guide ★ ☚ ☛ ★ Knowledge Base ★ ☚ ☛ ★ Troubleshooting ★ ☚ ● Be kind and nice. ● Stay on the topic. ● Post details. ● Search first. ● Please don't take it for granted. ● No email confidentiality should be violated. ● S/N, MAC, and your true public IP should be mosaiced.
Recommended Solution
  0  
  0  
#4
Options
4 Reply
Re:New here - Looking for ability to do whitelist blocking based on remote IP+destination IP and Port
Monday

Hi @ohaya1001 

Thanks for posting in our business forum.

You can use this emulator to learn about the Omada system:

https://emulator.tp-link.com/5.11-605v2/index.html

 

As for the ACL, you expect to be, this router is not the same level as the Openwrt or routers that supports iptables configuration.

It can do basic ACL for IP and Port but is not as granular as an Openwrt system.

Best Regards! If you are new to the forum, please read: Howto - A Guide to Use Forum Effectively. Read Before You Post. Look for a model? Search your model NOW Official and Beta firmware. NEW features! Subscribe for the latest update!Download Beta Here☚ ☛ ★ Configuration Guide ★ ☚ ☛ ★ Knowledge Base ★ ☚ ☛ ★ Troubleshooting ★ ☚ ● Be kind and nice. ● Stay on the topic. ● Post details. ● Search first. ● Please don't take it for granted. ● No email confidentiality should be violated. ● S/N, MAC, and your true public IP should be mosaiced.
  0  
  0  
#2
Options
Re:New here - Looking for ability to do whitelist blocking based on remote IP+destination IP and Port
Monday

  @Clive_A 

 

Thanks for responding.  Can you clarify?  Would the Omada router be able to block incoming connections based on remote IP, and target IP and port?

 

FYI, my son, who works in networking (but not with Omada equipment) suggested:

 

https://www.amazon.com/dp/B0DDRC1T34

https://www.amazon.com/dp/B07GX6GVB6

 

Would that be able to block all incoming connections, other than the whitelisted one?

 

Thanks,

Jim

  0  
  0  
#3
Options
Re:New here - Looking for ability to do whitelist blocking based on remote IP+destination IP and Port-Solution
Monday - last edited 12 hours ago

Hi @ohaya1001 

Thanks for posting in our business forum.

ohaya1001 wrote

  @Clive_A 

 

Thanks for responding.  Can you clarify?  Would the Omada router be able to block incoming connections based on remote IP, and target IP and port?

 

FYI, my son, who works in networking (but not with Omada equipment) suggested:

 

https://www.amazon.com/dp/B0DDRC1T34

https://www.amazon.com/dp/B07GX6GVB6

 

Would that be able to block all incoming connections, other than the whitelisted one?

 

Thanks,

Jim

It is not perfect yet to specify the IP and Port like the Openwrt which you have many options and ways to achieve what you described.

It now has a limitation in Controller mode where you cannot specify the IP-Port Group in the directions.

 

For other aspects, see this:

ACL Guide Compilation

What worries me is that it might not be what you are after. So to avoid that, you can see the common implementation of this router.

Emulator of the controller: https://support.omadanetworks.com/en/product/omada-software-controller/v5/?resourceType=tool

Best Regards! If you are new to the forum, please read: Howto - A Guide to Use Forum Effectively. Read Before You Post. Look for a model? Search your model NOW Official and Beta firmware. NEW features! Subscribe for the latest update!Download Beta Here☚ ☛ ★ Configuration Guide ★ ☚ ☛ ★ Knowledge Base ★ ☚ ☛ ★ Troubleshooting ★ ☚ ● Be kind and nice. ● Stay on the topic. ● Post details. ● Search first. ● Please don't take it for granted. ● No email confidentiality should be violated. ● S/N, MAC, and your true public IP should be mosaiced.
Recommended Solution
  0  
  0  
#4
Options
Re:New here - Looking for ability to do whitelist blocking based on remote IP+destination IP and Port
Monday

Thanks - I did take a cursory look at the emulator, but will do a more in depth look.

 

 

  0  
  0  
#5
Options