Y
Y
Your Kalash2015-05-26 17:04:40
ASUS
Your Kalash, 2015-05-26 17:04:40

Setting up access from LAN to WAN in ASUS routers (upd. answer below)?

...here I recently discovered an unpleasant thing at work
. The bottom line is this:
there are 3 ASUS routers at work, there is a separate gateway that gives addresses (not DHCP) and Internet access to wired users, so the Internet also comes from this gateway to these routers, but the trick is that after setting up the router, I freely ping and work with the WAN network.
example:
192.168.1.1-254 is the router's LAN network
192.168.10.1-254 is the organization's network, from where the WAN comes to the router, it
turns out that I can freely ping anything and knock from the LAN network to the WAN network, attach network drives, rummage through resources. those. having an IP address of 192.168.1.15 I can ping 192.168.10.1-254 and cling to these resources
So the question is - how can I restrict access from LAN to WAN, so that no pings come, nor the general network is available. this is real? because no one needs such a hole in the network, I don’t need extra packets from wi-fi clients, especially any network worm.
UPDATE
generally contacted support, they said that routers serve for this, that if they try to block access to the internal WAN network, then you will lose the Internet, so the only solution is to create another network closed from the public network.

Answer the question

In order to leave comments, you need to log in

1 answer(s)
Y
Your Kalash, 2015-05-26
@SySyS

And what do you have there that distributes addresses and not dhcp at the same time?

Yes, the usual gateway software is Kerio, but it does not distribute, but sets it on its own, with a prescription for each user of a specific address in the network properties. I expressed myself badly.
Well, by default, apparently yes ...
that's the point - how to register this item in the router, in one of the routers I found a filter in the firewall of packets and ICMP requests (in particular, now I managed to block ping from lan to wan, but this is just ping, and go to any machine from the network is still possible
c53ddcc5021b4d41bd3dded386f7a0dd.png

Didn't find what you were looking for?

Ask your question

Ask a Question

731 491 924 answers to any question