D-Link DSR-Series User Manual 146
Section 8 - Security
Path: Security > Firewall > Firewall Rules > IPv4 Firewall Rules or IPv6 Firewall Rules
Inbound (WAN to LAN/DMZ) rules restrict access to traī¬c entering your network, selectively allowing only
speciīæc outside users to access speciīæc local resources. By default all access from the insecure WAN side are
blocked from accessing the secure LAN, except in response to requests from the LAN or DMZ. To allow outside
devices to access services on the secure LAN, you must create an inbound īærewall rule for each service.
If you want to allow incoming traī¬c, you must make the routerās WAN port IP address known to the public. This is
called āexposing your host.ā How you make your address known depends on how the WAN ports are conīægured;
for this router you may use the IP address if a static address is assigned to the WAN port, or if your WAN address
is dynamic a DDNS (Dynamic DNS) name can be used.
Outbound (LAN/DMZ to WAN) rules restrict access to traī¬c leaving your network, selectively allowing only
speciīæc local users to access speciīæc outside resources. The default outbound rule is to allow access from
the secure zone (LAN) to either the public DMZ or insecure WAN. On other hand the default outbound rule
is to deny access from DMZ to insecure WAN. You can change this default behavior in the Firewall Settings >
Default Outbound Policy page. When the default outbound policy is allow always, you can to block hosts on
the LAN from accessing internet services by creating an outbound īærewall rule for each service.
To create a new īærewall rule:
1. Click Security > Firewall > IPv4 Firewall Rules tab or IPv6 Firewall Rules tab.
Firewall
Firewall Rules
2. Right-click an entry and select either Edit or Delete. To add a new group, click Add New IPv4/IPv6
Firewall Rule.