This article describes how to restrict FTP service from LAN clients by using the Firewall function to block the traffic on TCP port 21. In this example, we want to create a firewall rule for all the LAN clients. The configuration necessary is shown below.
Note: We only need to create firewall rules for the outgoing traffic (from LAN to WAN), since the router is already blocking all the incoming traffic by default
1. Go to Object Setting >> Services Type Object to create a profile as follows:
2. Go to Firewall >> Filter Setup >> Filter Set 2, click on an empty rule and edit as follows:
3. The firewall rule will be active as long as it is enabled. From Diagnostics >> Syslog Explorer, we may see the router has blocked the attempts of connecting to TCP port 21
1. Go Security / Firewall Filters / IP Filters. Add a rule in IP Filters and configure it as follows.
Then click Apply to save the settings.
2. In Monitoring / Log Center. We can see the router has blocked the attempts to connect the FTP server.
1. Go to Object Setting >> Services Type Object to create a profile as follows:
2. Go to Firewall >> Filter Setup >> IP Filter, create an IP Filter Group and add a rule as follows:
As long as the filter rule is enabled, it will be active. We may go to System Maintenance >> Syslog / Mail Alert >> Syslog File to see if the router has filtered any FTP traffic.
Published On: 2017-05-16
Was this helpful?