Vigor router supports Country Object. With this feature, it will be easier for the network administrator to allow or block access to an IP address of a specific country. For example, the network administrator can block certain countries from connecting the port to access the internal server to prevent attacks. Or, to restrict the destination that LAN users can access to the selected countries only. This note demonstrates how to allow the LAN hosts to access the UK websites only.
1. Create a Country Object. Go to Objects Setting >> Country Object page. Click an available index, give a profile Name and select Country.
To block all websites except for those in the UK, we will need to create two firewall rules. The first one to block all websites, and the second to allow access to websites in the UK.
2. Create the rule blocks all sites, go to Firewall >> Filter Setup >> Default Data Filter Set, and click an available rule to edit.
a. Select “Any” for Source IP, Destination IP, and Service Type
b. Select “Block if no further Match” for Action, so the router will check the other rules first
3. Create another rule to allow access to the websites of the UK. Go back to Default Data Filter page, and click an available rule which follows behind the rule created in the previous step.
a. Click Edit behind the Destination IP/Country to select Country Object created in the first step
b. Select “Pass Immediately” for Action
4. Now create another rule to allow DNS to go through
5: Now try to access a few websites to verify the firewall setting.
6: Note – a good tool to use is the syslog
When the DNS filter is off the syslog shows a block on 220.127.116.11 Hence step 4 included above.