cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1128
Views
0
Helpful
3
Replies

RV325 creating access rules

nbaker011
Level 1
Level 1

Hello, I can't seem to figure out how the access rules on the RV325 are supposed to work (assuming they are supposed to work). Say I have an application I want to let through the firewall from a specific address on WAN1, I create a rule that allows that ipaddress/port from WAN1 to the target on the LAN side, e.g:

Allow, Service FTP[21], Source Interface WAN1, Source 10.10.10.50-10.10.10.50 Destination 192.168.0.80-192.168.0.80, Time Always

(confusingly it still reports as a range even thought I enter as Single address)

If I try to access that then from the source I don't get through. Nothing in the access log in terms of DENY/ALLOW either.

So then I enable Port Forwarding or Port Address Translation and it works. But from the log I see 100's of access attempts getting through from random IP addresses as well, so Firewall is being ignored, yikes.

Anyone have a configuration example that works here?

3 Replies 3

nbaker011
Level 1
Level 1

Tried the same scenario out on a 800 series router and it worked as expected. Something odd with the RV325. Solution seems to be to upgrade to something that works.

florian.pele
Level 1
Level 1

I have a brand new RV325 that does not allow any inbound  access through WAN1. I upgraded to 1.3.2.02, tried one-to-one NAT, port forwarding, access rules....., even tried turning off the firewall and still it would not allow any WAN1 originating inbound traffic. I have a web server and SSH access I need to configure. The real problem is that I am really pressed for time....I have 7 days to get this working!

Any ideas?

Ami Xiao
Level 1
Level 1

Hi, I just did some testing on my RV325, it seems works fine. Only the specific PC 1.x.x.x able to access web service in LAN side.

  1. enable port forwarding to web server in RV325 LAN 172.16.1.102
  2. and I've add two access rule as below.
Allow HTTP Secondary [8080] WAN1 1.x.x.x ~ 1.x.x.x 172.16.1.102 ~ 172.16.1.102 Always
Deny All Traffic [1] WAN1 Any Any Always