Got it

AR1220VW functions as a firewaal on a wireless network

Created: Mar 29, 2017 06:47:30Latest reply: Aug 28, 2017 00:51:25 1545 2 0 0 0
  Rewarded HiCoins: 0 (problem resolved)

good day,

 

please assist, the network is a wireless network with and adsl router and a wireless router as an AP and Dhcp server for about 100 users.

i want to configure firewall on the AR, so that users cannot access the internet, only access specific educational sites.

configured as per below, the AR has an uplink to the Wireless router(ASUS) ,Adsl router connects to the wireless router.

after configurations as below, the user can still access the internet.

 

please assist, what did i nt do or did wrong?

 

 

[V200R007C00SPC600]
#
 drop illegal-mac alarm
#
vlan batch 100
#
pki realm default
 enrollment self-signed
#
ssl policy default_policy type server
 pki-realm default
#
acl number 3000
 description DENY
 rule 5 permit ip source 192.168.210.222 0
 rule 10 deny tcp source 192.168.210.222 0 destination-port eq www
#
aaa
 authentication-scheme default
 authorization-scheme default
 accounting-scheme default
 domain default
 domain default_admin
 undo local-user admin
 local-user user password irreversible-cipher %^%#o1D!")ma#>N7^!1-Xr)4e.q/,h@by!ZK3=0!$8P>_<;e.G(K"G=N*c=Il[s@%^%#
 local-user user privilege level 15
 local-user user service-type http
#
firewall zone IN
 priority 15
#
firewall zone OUT
 priority 3
#
firewall zone Local
 priority 16
#
firewall interzone IN OUT
 firewall enable
 packet-filter 3000 inbound
#
interface Vlanif100
 ip address 10.0.0.5 255.255.255.0
#
interface Ethernet0/0/0
#
interface Ethernet0/0/1
#
interface Ethernet0/0/2
#
interface Ethernet0/0/3
#
interface Ethernet0/0/4
#
interface Ethernet0/0/5
#
interface Ethernet0/0/6
#
interface Ethernet0/0/7
#
interface GigabitEthernet0/0/0
 ip address 192.168.1.1 255.255.255.0
#
interface GigabitEthernet0/0/1
 description Uplinkto ASUS Router
 ip address 192.168.210.11 255.255.255.0
 traffic-filter inbound acl 3000
#
interface Cellular0/0/0
#
interface Cellular0/0/1

Featured Answers
Hi,

You should change the order of your ACL. Rule 10 trying to deny www traffic but Rule 5 already permits all IP traffic so Rule 10 is not even looked at. Try to change you rule order as first deny www traffic then permit all IP traffic.

Best Regards,
View more

Rating

Number of participants 1E-coins +10 Experience +1 Collapse Reasons
社区管理员咕噜噜 + 1 Good!
社区管理员咕噜噜 + 10 Good!

View All scores

  • x
  • convention:

All Answers
Hi,

You should change the order of your ACL. Rule 10 trying to deny www traffic but Rule 5 already permits all IP traffic so Rule 10 is not even looked at. Try to change you rule order as first deny www traffic then permit all IP traffic.

Best Regards,
View more

Rating

Number of participants 1E-coins +10 Experience +1 Collapse Reasons
社区管理员咕噜噜 + 1 Good!
社区管理员咕噜噜 + 10 Good!

View All scores

  • x
  • convention:

Actually detail related to functions as a firewaal on a wireless network, you like to write here. Some good piece of information related to this topic you like to posted here. However, I want to know about http://college-paper-writing-service.reviews/ but i felt this website is sound good due to valuable piece of content.
View more
  • x
  • convention:

Comment

You need to log in to comment to the post Login | Register
Comment

Notice: To protect the legitimate rights and interests of you, the community, and third parties, do not release content that may bring legal risks to all parties, including but are not limited to the following:
  • Politically sensitive content
  • Content concerning pornography, gambling, and drug abuse
  • Content that may disclose or infringe upon others ' commercial secrets, intellectual properties, including trade marks, copyrights, and patents, and personal privacy
Do not share your account and password with others. All operations performed using your account will be regarded as your own actions and all consequences arising therefrom will be borne by you. For details, see " User Agreement."

My Followers

Login and enjoy all the member benefits

Login

Block
Are you sure to block this user?
Users on your blacklist cannot comment on your post,cannot mention you, cannot send you private messages.
Reminder
Please bind your phone number to obtain invitation bonus.