What's new

RT-AC68U and Black List options

  • SNBForums Code of Conduct

    SNBForums is a community for everyone, no matter what their level of experience.

    Please be tolerant and patient of others, especially newcomers. We are all here to share and learn!

    The rules are simple: Be patient, be nice, be helpful or be gone!

Noki388

New Around Here
Looking for some assistance please,

I have an Asus RT-AC68U router and have Dahua NVR with cameras. The NVR is connect via ethernet to the router and cameras are connected to the NVR so are on a "subnet".

I want to block all outgoing connection from the NVR with the exception of port 2195. The reason for this is that I want it to send notifications to my iphone. Reading this and other forums, I understand that Apple requires port 2195 (and 2197 for newer device) open for its Apple Push Notification.

I am wanting advice on how to set it up. It seems to have the following options under Firewall -> Network Services Filter:
- Source IP: I presume this is the IP address of the NVR
- Port range: ?
- Destination IP: I presume I leave this blank
- Port range: ?
- Protocol: I presume TCP. Do I also need UDP?

With the port range, do I choose the port range for the Destination IP as I presume this is the Apple Push Notification? Or is it the Source IP port range?

As I want to block all ports except 2195, what is the best way to do this? Do I need to setup 2 separate options
eg first with 1:2194 and second with 2196:65535

Thanks
 
Been doing some reading and came up with a possible solution but wanted to get some opinions in regards whether it is a safe and suitable option.

Essentially I want to block all outgoing connections from my Dahua NVR with the exception of port 2195 for iOS notifications.

Under firewall -> Network services filter -> Blacklist
Source IP - xxx.x.xxx.x
Port range -
Destination IP -
Port range - 1:2194
TCP

Source IP - xxx.x.xxx.x
Port range -
Destination IP -
Port range - 2196:65535
TCP

I have only done it for TCP protocol, do I need to also do it for UDP protocol?

It seems to work as on the Connections tab, I see that the IP address is blocked whereas previously it was connecting to an outside IP.

I only have the offical Asus firmware but noticed that on the Merlin firmware, there seems to be options with both jffs scripts and Skynet. With what I have done, is it still doing the same thing.

Thanks
 

Latest threads

Sign Up For SNBForums Daily Digest

Get an update of what's new every day delivered to your mailbox. Sign up here!
Top