NETGEAR is aware of a growing number of phone and online scams. To learn how to stay safe click here.

Forum Discussion

Owen6936's avatar
Owen6936
Aspirant
Dec 12, 2018

Whitelist external IP Range for Port Forwarding - ORBI RBR50 -

We use an external service that requires ports to be open and redirected to internal printers, to be able to receive and print.  Hackers are scanning for open port and sending "improper" printouts to our printers.  Is there a way to "whitelist" an IP range so ONLY the IP addresses in that range are allowed access to those ports?

7 Replies

    • CrimpOn's avatar
      CrimpOn
      Guru

      You did not say what brand/model of printers are involved.  In addition to trying to block the most common types of port scanning (ping, etc.), it might be worth a few minutes to Google "how to block IP addresses from printing."  For example, there is thread on an HP help site:

      https://h30434.www3.hp.com/t5/LaserJet-Printing/Restrict-printing-by-IP/td-p/5981470

       

      At message 4, "John" talks about setting up an old Windows PC as a print server, which enables all of the capabilities of Windows Firewall.  He also talks about capabilities inherent in the specific HP print server they were discussing.  A PC is certainly more expensive than a ream of dirty pictures, but also less costly than a hostile workplace lawsuit.

       

      Their specific problem was related to the print server being able to block access to port 80, but not blocking access "directly to the printer."  What IP port(s) are being used remotely to access your printers?

      • Owen6936's avatar
        Owen6936
        Aspirant

        We use several ports, like 9001, 9002, 9003, 9004, 9005, 9100.  They are mapped to an internal IP address on the internal port of 9100, using the "gaming" section of the router.

         

        port: 9001, redirected to 192.168.1.42 port 9100 (as an example).

         

        There is only one outside range of IP addresses that I want to Allow access (passage) to and through these ports.  I want to deny every other attempt/access.

         

        The ISP is Sudden Link, they provided a ARRIS Touchstone SB6183. Modem.