<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic RV082 Access Rules in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/rv082-access-rules/m-p/1886106#M457078</link>
    <description>&lt;P&gt;Good Day To All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; We recently purchased a RV082 Firewall Router and I am having the headache of a lifetime with the access rules and port forwarding. I have read EVERY post possible and still cannot come to a conclusion of what I am doing wrong...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;First Question&lt;/STRONG&gt; is the MAIL SERVER.. I could not get our email server to talk when setting this device to DMZ so for the time being I put it on LAN2 and attempted to set up an access rule Port 25 to the IP of the mail server. NO GO.. I had to port forward or it would not work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now I want to deny access on port 25 over WAN1 201.X.X.108 but allow access over port 25 on WAN2 201.X.X.109 and this is where it's a NO GO. It doesnt matter what order I put the rules in, its still a no go. Furthermore if I take out the port forward 25 and put in the rules to allow ANY source to reach 25 on the mail server it ALSO does not work...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is what I have now and I can still access the email server on EITHER WAN address. I have tried to specifically DENY WAN1 but still no luck.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;FORWARD:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;PORT 25 to 192.168.0.221 is ENABLED&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;ACCESS RULES: &lt;SPAN style="font-size: 8pt;"&gt;(in this order)&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;ACTION:&lt;/STRONG&gt; ALLOW&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;SERVICE:&lt;/STRONG&gt; SMTP:25&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;SOURCE INTERFACE:&lt;/STRONG&gt; WAN2&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;SOURCE:&lt;/STRONG&gt; ANY&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;DESTINATION:&lt;/STRONG&gt; 192.168.0.221&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;TIME:&lt;/STRONG&gt; ALWAYS&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;ACTION:&lt;/STRONG&gt; ALLOW&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;SERVICE:&lt;/STRONG&gt; SMTP:25&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;SOURCE INTERFACE:&lt;/STRONG&gt; LAN&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;SOURCE:&lt;/STRONG&gt; 192.168.0.221&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;DESTINATION:&lt;/STRONG&gt; ANY&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;TIME:&lt;/STRONG&gt; ALWAYS&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;ACTION:&lt;/STRONG&gt; DENY&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;SERVICE&lt;/STRONG&gt;: SMTP:25&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;SOURCE INTERFACE:&lt;/STRONG&gt; ANY&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;SOURCE:&lt;/STRONG&gt; ANY&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;DESTINATION:&lt;/STRONG&gt; ANY&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;TIME:&lt;/STRONG&gt; ALWAYS&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Now Second Question&lt;/STRONG&gt; is pretty much the same but with SSH on port 22. I did this as a test and enabled SSH to the mail server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;FORWARD:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;NOTHING SET&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;ACTION:&lt;/STRONG&gt; ALLOW&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;SERVICE:&lt;/STRONG&gt; SSH:22&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;SOURCE INTERFACE:&lt;/STRONG&gt; ANY&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;SOURCE:&lt;/STRONG&gt; ANY&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;DESTINATION:&lt;/STRONG&gt; 192.168.0.221&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;TIME:&lt;/STRONG&gt; ALWAYS&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Why would this not work? The ONLY was I can get an SSH:22 to work is if I port forward it and then the access rule when set to DENY ALL it still allows it on both WAN1 and WAN2...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;CONFUSED!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HELP!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PLEASE!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The Screen shot was my last attempt at making SSH work...&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 22:53:20 GMT</pubDate>
    <dc:creator>richardhassell</dc:creator>
    <dc:date>2019-03-11T22:53:20Z</dc:date>
    <item>
      <title>RV082 Access Rules</title>
      <link>https://community.cisco.com/t5/network-security/rv082-access-rules/m-p/1886106#M457078</link>
      <description>&lt;P&gt;Good Day To All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; We recently purchased a RV082 Firewall Router and I am having the headache of a lifetime with the access rules and port forwarding. I have read EVERY post possible and still cannot come to a conclusion of what I am doing wrong...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;First Question&lt;/STRONG&gt; is the MAIL SERVER.. I could not get our email server to talk when setting this device to DMZ so for the time being I put it on LAN2 and attempted to set up an access rule Port 25 to the IP of the mail server. NO GO.. I had to port forward or it would not work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now I want to deny access on port 25 over WAN1 201.X.X.108 but allow access over port 25 on WAN2 201.X.X.109 and this is where it's a NO GO. It doesnt matter what order I put the rules in, its still a no go. Furthermore if I take out the port forward 25 and put in the rules to allow ANY source to reach 25 on the mail server it ALSO does not work...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is what I have now and I can still access the email server on EITHER WAN address. I have tried to specifically DENY WAN1 but still no luck.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;FORWARD:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;PORT 25 to 192.168.0.221 is ENABLED&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;ACCESS RULES: &lt;SPAN style="font-size: 8pt;"&gt;(in this order)&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;ACTION:&lt;/STRONG&gt; ALLOW&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;SERVICE:&lt;/STRONG&gt; SMTP:25&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;SOURCE INTERFACE:&lt;/STRONG&gt; WAN2&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;SOURCE:&lt;/STRONG&gt; ANY&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;DESTINATION:&lt;/STRONG&gt; 192.168.0.221&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;TIME:&lt;/STRONG&gt; ALWAYS&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;ACTION:&lt;/STRONG&gt; ALLOW&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;SERVICE:&lt;/STRONG&gt; SMTP:25&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;SOURCE INTERFACE:&lt;/STRONG&gt; LAN&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;SOURCE:&lt;/STRONG&gt; 192.168.0.221&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;DESTINATION:&lt;/STRONG&gt; ANY&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;TIME:&lt;/STRONG&gt; ALWAYS&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;ACTION:&lt;/STRONG&gt; DENY&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;SERVICE&lt;/STRONG&gt;: SMTP:25&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;SOURCE INTERFACE:&lt;/STRONG&gt; ANY&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;SOURCE:&lt;/STRONG&gt; ANY&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;DESTINATION:&lt;/STRONG&gt; ANY&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;TIME:&lt;/STRONG&gt; ALWAYS&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Now Second Question&lt;/STRONG&gt; is pretty much the same but with SSH on port 22. I did this as a test and enabled SSH to the mail server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;FORWARD:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;NOTHING SET&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;ACTION:&lt;/STRONG&gt; ALLOW&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;SERVICE:&lt;/STRONG&gt; SSH:22&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;SOURCE INTERFACE:&lt;/STRONG&gt; ANY&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;SOURCE:&lt;/STRONG&gt; ANY&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;DESTINATION:&lt;/STRONG&gt; 192.168.0.221&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;TIME:&lt;/STRONG&gt; ALWAYS&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Why would this not work? The ONLY was I can get an SSH:22 to work is if I port forward it and then the access rule when set to DENY ALL it still allows it on both WAN1 and WAN2...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;CONFUSED!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HELP!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PLEASE!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The Screen shot was my last attempt at making SSH work...&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 22:53:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/rv082-access-rules/m-p/1886106#M457078</guid>
      <dc:creator>richardhassell</dc:creator>
      <dc:date>2019-03-11T22:53:20Z</dc:date>
    </item>
    <item>
      <title>Re: RV082 Access Rules</title>
      <link>https://community.cisco.com/t5/network-security/rv082-access-rules/m-p/1886107#M457084</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Esentially what I am trying to accomplish is to NOT have the port forward set. But in every case so far it seems as if the access rules DO NOT WORK at all. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Even if I set SSH:22 to port forward and set a firewall rule to DENY ANY ANY ANY to ANY I can still SSH to the box &lt;SPAN __jive_emoticon_name="sad" __jive_macro_name="emoticon" class="jive_macro jive_emote" height="16" src="https://community.cisco.com/4.5.4/images/emoticons/sad.gif" width="16"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 Apr 2012 21:36:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/rv082-access-rules/m-p/1886107#M457084</guid>
      <dc:creator>richardhassell</dc:creator>
      <dc:date>2012-04-12T21:36:41Z</dc:date>
    </item>
  </channel>
</rss>

