NETGEAR is aware of a growing number of phone and online scams. To learn how to stay safe click here.

Forum Discussion

Ahiro's avatar
Ahiro
Aspirant
Oct 28, 2016
Solved

Firewall rules with softwares and VPN

Hello everybody!

 

I'm trying to configure our new firewall in order to securise our network but I got some questions :

 

- How to configure firewall rules? I mean I got several softwares I use to work with and I don't want them to be blocked. Must I configure a new service and then use inbound/outbound rules to allow them? If yes how can I know the port they are using?

 

- I want to use the VPN server in our Firewall. Should I create some specific rules to connect myself to the network remotely or will the Firewall let me pass through it?

 

- My Firewall is right behind the modem. Should I configure my modem in bridge mode in order to access to the VPN server?

 

Thank you for your reply! I stay tuned ;)

  • Hi Ahiro,

     

    If you are referring to the FVS336Gv3 to be used as a modem, I am certain this is not possible.  I suggest you to contact your ISP and request them to change your modem to one that is configurable to bridge mode. 

     

     

    Regards,

     

    DaneA

    NETGEAR Community Team

9 Replies

  • Oh and the last question :

     

    Can I delete the modem before in order to use the VPN server or can I let the modem?

    The modem don't got any bridge mode...

     

    Here is my configuration :

     

    Internet => Modem (FritzBox) => FVS336Gv3 => Internal network

     

    So there is a network between modem and firewall at the moment and another network after the firewall.

     

    It would be nice if the firewall can be used as a modem but I don't think so...

    • JohnRo's avatar
      JohnRo
      NETGEAR Employee Retired

      Hello Ahiro, 

       

      Welcome to the community! 

       

      I have listed down your questions and my answers will be below each one of them: 

       

      - How to configure firewall rules? I mean I got several softwares I use to work with and I don't want them to be blocked. Must I configure a new service and then use inbound/outbound rules to allow them? If yes how can I know the port they are using?

      -To configure firewall rules, go to Security>Firewall Rules

      -There is a pre-defined list of rules that you can already use, if you do not see the service that you are looking for then that is the time you will add a custom service. 

      -You will have to check it on the device/software itself. See the manual or ask the manufacturer. The firewall does not have the option to see what ports the devices are using. 

       

       

      - I want to use the VPN server in our Firewall. Should I create some specific rules to connect myself to the network remotely or will the Firewall let me pass through it?

      -No rules necessary, once it is connected to the tunnel you should be able to access the resources on the remote network unless you have defined a specific rule on one of them. 

       

       

      - My Firewall is right behind the modem. Should I configure my modem in bridge mode in order to access to the VPN server?

      -Yes, you'll need to have it bridged. If there is no option to bridge it then check if it has a DMZ port option. The DMZ will forward all request to the FVS336Gv3. 

      -This should also answer you last question. 

       

      Let me know if this helps. 

       

      Thanks, 

       

      • Ahiro's avatar
        Ahiro
        Aspirant

        Thank you for your reply!

         

        So I've just checked my modem : no bridge more and no DMZ... Such a crap!

         

        So I tried to forward all of the ports to my Firewall but it didn't work! The modem (FritzBox) still keep VPN packets for itself and doesn't give them to the firewall and I can't stop that...

         

        So here is my last question : Can I use the FVS336Gv3 as a modem integrating VPN server at the same time? This way I (hope) 'll be able to access to the VPN server with WAN ip address and my LAN network will still get connexion to the Internet.

         

        Tell me if this is possible please...

         

        Thank you!

NETGEAR Academy

Boost your skills with the Netgear Academy - Get trained, certified and stay ahead with the latest Netgear technology! 

Join Us!

ProSupport for Business

Comprehensive support plans for maximum network uptime and business peace of mind.

 

Learn More