VPN and Port block

Post new topic   Reply to topic    DD-WRT Forum Index -> Atheros WiSOC based Hardware
Author Message
drnorton
DD-WRT User


Joined: 08 Dec 2009
Posts: 137

PostPosted: Wed Aug 30, 2017 9:44    Post subject: VPN and Port block Reply with quote
Hello...
I have a question about some Port block.
I have a VPN Server running on dd-wrt.
I can login with the cliensts and everything runs well.
The Clients become the IP Adress range 10.1.1.0/24
and the LAN has the range 192.168.6.0/24.

Now I like to block some ports for VPN.
With Iptabels or with access rescrictions.
Please help me.

I have write this in my Firewall.
iptables -I FORWARD -s 10.1.1.0/24 -p tcp --dport 27000:27050 -j DROP
iptables -I FORWARD -s 10.1.1.0/24 -p udp --dport 27000:27050 -j DROP

But this dont work.

Many thanks in advance!
drnorton
Sponsor
tatsuya46
DD-WRT Guru


Joined: 03 Jan 2010
Posts: 7568
Location: YWG, Canada

PostPosted: Wed Aug 30, 2017 9:48    Post subject: Reply with quote
did u look at access restrictions page..? u can create whatever port+protocol & ipranges etc
_________________
LATEST FIRMWARE(S)

BrainSlayer wrote:
we just do it since we do not like any restrictions enforced by stupid cocaine snorting managers

[x86_64] Haswell i3-4150/QCA9984/QCA9882 ------> r55797 std
[QUALCOMM] DIR-862L --------------------------------> r55797 std
▲ ACTIVE / INACTIVE ▼
[QUALCOMM] WNDR4300 v1 --------------------------> r50485 std
[BROADCOM] DIR-860L A1 ----------------------------> r50485 std


Sigh.. why do i exist anyway.. | I love you Anthony.. never forget that.. my other 99% that ill never see again..

drnorton
DD-WRT User


Joined: 08 Dec 2009
Posts: 137

PostPosted: Wed Aug 30, 2017 10:09    Post subject: Reply with quote
Yes I have. But it dont go.
I have make new Port ranges for blocking
and get the ip adress range 10.1.1.0 to 10.1.1.254.
But no blocking.
I dont know why..
Is a tplink 1043 v.1 28882 dd-wrt.
Newer one vpn and access restriction dont go.
tatsuya46
DD-WRT Guru


Joined: 03 Jan 2010
Posts: 7568
Location: YWG, Canada

PostPosted: Wed Aug 30, 2017 10:23    Post subject: Reply with quote
update build first.. & make sure cron isnt disabled after that
_________________
LATEST FIRMWARE(S)

BrainSlayer wrote:
we just do it since we do not like any restrictions enforced by stupid cocaine snorting managers

[x86_64] Haswell i3-4150/QCA9984/QCA9882 ------> r55797 std
[QUALCOMM] DIR-862L --------------------------------> r55797 std
▲ ACTIVE / INACTIVE ▼
[QUALCOMM] WNDR4300 v1 --------------------------> r50485 std
[BROADCOM] DIR-860L A1 ----------------------------> r50485 std


Sigh.. why do i exist anyway.. | I love you Anthony.. never forget that.. my other 99% that ill never see again..

drnorton
DD-WRT User


Joined: 08 Dec 2009
Posts: 137

PostPosted: Wed Aug 30, 2017 10:46    Post subject: Reply with quote
Ok I will test it.
Thanks...
drnorton
DD-WRT User


Joined: 08 Dec 2009
Posts: 137

PostPosted: Wed Aug 30, 2017 11:52    Post subject: Reply with quote
I changed to build nr. 33257.
VPN dont work. Cron is enabled.

In access restricion I can only block Ip adresses
from my LAN. Or ?
I think I must block the Ip Adress 10.1.1.1 till 10.1.1.254

It does not go.
Display posts from previous:    Page 1 of 1
Post new topic   Reply to topic    DD-WRT Forum Index -> Atheros WiSOC based Hardware All times are GMT

Navigation

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You cannot download files in this forum