Page 1 of 1

Manage Access List, Web Traffic and rule questions.

Posted: Fri Oct 10, 2014 3:35 pm
by sdevries.otn
I am currently working on setting up a VPN group for RDP users. I am setting it up as a white list style filter, my last two rules will discard all to, or from, the group. Then I pass only what is actually wanted/needed for RDP/internet. I have some questions though.

Can you specify multiple protocol numbers for a single rule? (EX: TCP and UDP, but not "any" / all.)
Can you specifiy multiple port(s) / ranges for a single rule? (EX: 500, 5555-5575)
(Currently, I do not think either can be done, but they would be nice features. It would cut the number of rules I have in half, and make it easier to manage them.)

Is there a simple way to pass web traffic to / from the internet?
My last two rules were, correctly so, discarding all web traffic. I'd like to open that up for VPN users. Currently, I am passing from <group> to any TCP ports 80, 8080, 443. Should I limit Destination to 0.0.0.0? Or open any other ports?

Re: Manage Access List, Web Traffic and rule questions.

Posted: Thu Oct 23, 2014 7:43 am
by thisjun
> Is there a simple way to pass web traffic to / from the internet?
It depends on your definition of Internet.

Re: Manage Access List, Web Traffic and rule questions.

Posted: Mon Oct 27, 2014 3:40 pm
by sdevries.otn
By internet, I mean destinations outside of our personal network/subnet. (We do not have multiple sites, so no "WAN").

Re: Manage Access List, Web Traffic and rule questions.

Posted: Thu Nov 06, 2014 6:55 am
by thisjun
Please allow all packets from/to port 80 and 443. You don't need to limit IP address.