Results 1 to 16 of 16

Thread: Anyone familiar with draytek routers?

  1. #1
    Senior Member
    Join Date
    Mar 2005
    Posts
    4,826
    Thanks
    161
    Thanked
    358 times in 288 posts
    • badass's system
      • Motherboard:
      • ASUS P8Z77-m pro
      • CPU:
      • Core i5 3570K
      • Memory:
      • 32GB
      • Storage:
      • 1TB Samsung 850 EVO, 2TB WD Green
      • Graphics card(s):
      • Radeon RX 580
      • PSU:
      • Corsair HX520W
      • Case:
      • Silverstone SG02-F
      • Operating System:
      • Windows 10 X64
      • Monitor(s):
      • Del U2311, LG226WTQ
      • Internet:
      • 80/20 FTTC

    Anyone familiar with draytek routers?

    A simple problem. I have multiple IP addresses as I need several machines in the network to have their own, unique non NAT'd IP address.
    I have set the router up successfully in this config and the machines behind it can access the internet or be accessed from the internet.
    The problem is the fecking firewall
    It is supposed to be a stateful firewall, but I cant get it to work properly.
    The manual that came with it is worse than useless. The more comprehensive manual that is available from ftp.draytek.co.uk is also useless. The message boards after extensive searching do have a few topics with people that have the same problem, however there are no answers
    I just want it to allow all outgoing for now, and block all incoming apart from packets related to sessions allready open. I will worry about the rest once I have this working.

    Kind of like the protection you get from sitting behind a NAT firewall.

    I would also be interested in a description of what the keep state checkbox actually does (it sure doesn't work as I expected) and will only stay on when set on rules to deny connections.
    Please bare in mind with any replies, I know how firewalls work and have set up numerous other ones (in fact I've set up loads of these particualr ones in NAT mode successfully)
    "In a perfect world... spammers would get caught, go to jail, and share a cell with many men who have enlarged their penises, taken Viagra and are looking for a new relationship."

  2. #2
    Administrator Moby-Dick's Avatar
    Join Date
    Jul 2003
    Location
    There's no place like ::1 (IPv6 version)
    Posts
    10,665
    Thanks
    53
    Thanked
    385 times in 314 posts
    I've had some interesting times with the draytek firewalls.

    Thbe default setup you've put down are what a statefull fw should do

    I know the rule setup is like a cisco type ruleset ie it works from top to bottom alsways taking the least access approach, but thats all for the moment. I'll have a hunt about and see if I can find anything that'll be of use
    my Virtualisation Blog http://jfvi.co.uk Virtualisation Podcast http://vsoup.net

  3. #3
    Senior Member Merlin4458's Avatar
    Join Date
    Dec 2004
    Location
    Kingston Uni
    Posts
    2,606
    Thanks
    26
    Thanked
    11 times in 11 posts
    i have had a draytek vigor 220 USB for 4 years now, i can get it too work, but got no idea what all the options to. Like NAT DNS, and also where the **** is the inbuilt firewall and how is it turned off?
    Rig: Amd 64 3700+ San Diego | Abit AT8 | 4x512 Corsair XMS3200C2PRO | PowerColour X850XTPE / Arctic Cooled | Samsung Spinpoint 250Gig | Enermax NoiseTake 485w | Arctic Freezer 64 Pro | Coolermaster Wavemaster Silver | Dell 2405FPW | Logitech G5 / Everglide Destrukt Monstermat |

  4. #4
    Senior Member
    Join Date
    Mar 2005
    Posts
    4,826
    Thanks
    161
    Thanked
    358 times in 288 posts
    • badass's system
      • Motherboard:
      • ASUS P8Z77-m pro
      • CPU:
      • Core i5 3570K
      • Memory:
      • 32GB
      • Storage:
      • 1TB Samsung 850 EVO, 2TB WD Green
      • Graphics card(s):
      • Radeon RX 580
      • PSU:
      • Corsair HX520W
      • Case:
      • Silverstone SG02-F
      • Operating System:
      • Windows 10 X64
      • Monitor(s):
      • Del U2311, LG226WTQ
      • Internet:
      • 80/20 FTTC
    It is now pretty obvious to me that draytek do not actually test the instructions or interfaces on people that have not designed the priduct.
    The state of their support and documentation is disgusting.
    The support on thir site says http://www.draytek.com/support/suppo...r_firewall.php

    Guess what?
    I do that and it DOESN'T WORK.

    I have now been trying a firmware upgrade. Their own firmware upgrade software doesn't work

    Just to confirm, I have created a rule to allow all outgoing. Another rule below it to allow all incoming with the keep state checkbox checked and a rule at the bottom saying deny all incoming. As said in the link above. The firewall does no filtering at all when I do this.

    You cant click keep state on the allow outgoing - it just forgets it.
    Last edited by badass; 30-10-2005 at 04:19 PM.
    "In a perfect world... spammers would get caught, go to jail, and share a cell with many men who have enlarged their penises, taken Viagra and are looking for a new relationship."

  5. #5
    Senior Member
    Join Date
    Mar 2005
    Posts
    4,826
    Thanks
    161
    Thanked
    358 times in 288 posts
    • badass's system
      • Motherboard:
      • ASUS P8Z77-m pro
      • CPU:
      • Core i5 3570K
      • Memory:
      • 32GB
      • Storage:
      • 1TB Samsung 850 EVO, 2TB WD Green
      • Graphics card(s):
      • Radeon RX 580
      • PSU:
      • Corsair HX520W
      • Case:
      • Silverstone SG02-F
      • Operating System:
      • Windows 10 X64
      • Monitor(s):
      • Del U2311, LG226WTQ
      • Internet:
      • 80/20 FTTC
    I remember when you could upgrade the firmware on a draytek router by clicking the upload firmware link and then selecting the firmware file. Nice and easy.
    The 2600VG however is not you click the link and it just switched on its TFTP server and you have to use their TFTP client that doesn't work to upload the file

    WHAT EVER HAPPENED TO PRODUCT TESTING
    "In a perfect world... spammers would get caught, go to jail, and share a cell with many men who have enlarged their penises, taken Viagra and are looking for a new relationship."

  6. #6
    The late but legendary peterb - Onward and Upward peterb's Avatar
    Join Date
    Aug 2005
    Location
    Looking down & checking on swearing
    Posts
    19,378
    Thanks
    2,892
    Thanked
    3,403 times in 2,693 posts
    If tyou are not using NAT, the NAT firewall will not work! (Obviously!) Most of the cheaper routers do not include firewall filtering in pass through mode (ie, where it is routing seperate IP addresses to specific machines). If you are doing that, you probably need to provide your own firewall arrangements. I'm NOT saying that the Draytek falls into this category (I have'nt used one) but you may find that to be the case. If you want the protection of NAT, just use the one IP address and set u[p port forwarding...

    Which ISP are you using?

  7. #7
    Administrator Moby-Dick's Avatar
    Join Date
    Jul 2003
    Location
    There's no place like ::1 (IPv6 version)
    Posts
    10,665
    Thanks
    53
    Thanked
    385 times in 314 posts
    Its not the NAT firewall he's trying to use.
    but I think the Draytek shoudl support firewalling in NON nat mode.

    one idea would be to use the box in NAT mode with WAN IP alias#s set up to allow multiple forwards for different IP's
    my Virtualisation Blog http://jfvi.co.uk Virtualisation Podcast http://vsoup.net

  8. #8
    The late but legendary peterb - Onward and Upward peterb's Avatar
    Join Date
    Aug 2005
    Location
    Looking down & checking on swearing
    Posts
    19,378
    Thanks
    2,892
    Thanked
    3,403 times in 2,693 posts
    Sorry - I didn't read the last bit of the original post thoroughly!
    (\__/)
    (='.'=)
    (")_(")

    Been helped or just 'Like' a post? Use the Thanks button!
    My broadband speed - 750 Meganibbles/minute

  9. #9
    Senior Member
    Join Date
    Mar 2005
    Posts
    4,826
    Thanks
    161
    Thanked
    358 times in 288 posts
    • badass's system
      • Motherboard:
      • ASUS P8Z77-m pro
      • CPU:
      • Core i5 3570K
      • Memory:
      • 32GB
      • Storage:
      • 1TB Samsung 850 EVO, 2TB WD Green
      • Graphics card(s):
      • Radeon RX 580
      • PSU:
      • Corsair HX520W
      • Case:
      • Silverstone SG02-F
      • Operating System:
      • Windows 10 X64
      • Monitor(s):
      • Del U2311, LG226WTQ
      • Internet:
      • 80/20 FTTC
    I've got the firewall working in a statefull manner but due to my requirements and the limitations of the rules, a bit of NATing will have to occur
    "In a perfect world... spammers would get caught, go to jail, and share a cell with many men who have enlarged their penises, taken Viagra and are looking for a new relationship."

  10. #10
    HEXUS.social member Agent's Avatar
    Join Date
    Jul 2003
    Location
    Internet
    Posts
    19,168
    Thanks
    735
    Thanked
    1,607 times in 1,045 posts
    Ive got a 2600VG too badass. I know its not going to help you much, but ive not had a problem updating the firmware. Might be worth double checking everything
    Quote Originally Posted by Saracen View Post
    And by trying to force me to like small pants, they've alienated me.

  11. #11
    Senior Member
    Join Date
    Mar 2005
    Posts
    4,826
    Thanks
    161
    Thanked
    358 times in 288 posts
    • badass's system
      • Motherboard:
      • ASUS P8Z77-m pro
      • CPU:
      • Core i5 3570K
      • Memory:
      • 32GB
      • Storage:
      • 1TB Samsung 850 EVO, 2TB WD Green
      • Graphics card(s):
      • Radeon RX 580
      • PSU:
      • Corsair HX520W
      • Case:
      • Silverstone SG02-F
      • Operating System:
      • Windows 10 X64
      • Monitor(s):
      • Del U2311, LG226WTQ
      • Internet:
      • 80/20 FTTC
    I eventually upgraded the firmware - The site does not make it clear which file you should be uploading
    I have, however now found out that the fecking firewall is now NOT working.
    The piece of useless junk was stopping me from making a PPTP connection to work but happily letting me RDP into one of my servers
    EDIT: I have forgot to link one filterset to the next one DOH!
    Firewall working again.
    Last edited by badass; 01-11-2005 at 01:35 PM.
    "In a perfect world... spammers would get caught, go to jail, and share a cell with many men who have enlarged their penises, taken Viagra and are looking for a new relationship."

  12. #12
    HEXUS.timelord. Zak33's Avatar
    Join Date
    Jul 2003
    Location
    I'm a Jessie
    Posts
    35,157
    Thanks
    3,105
    Thanked
    3,138 times in 1,916 posts
    • Zak33's system
      • Storage:
      • Kingston HyperX SSD, Hitachi 1Tb
      • Graphics card(s):
      • Nvidia 1050
      • PSU:
      • Coolermaster 800w
      • Case:
      • Silverstone Fortress FT01
      • Operating System:
      • Win10
      • Internet:
      • Zen FTC uber speedy
    Quote Originally Posted by badass
    I would also be interested in a description of what the keep state checkbox actually does (it sure doesn't work as I expected) and will only stay on when set on rules to deny connections.
    more in a mo

    Quote Originally Posted by Advice Trinity by Knoxville
    "The second you aren't paying attention to the tool you're using, it will take your fingers from you. It does not know sympathy." |
    "If you don't gaffer it, it will gaffer you" | "Belt and braces"

  13. #13
    HEXUS.timelord. Zak33's Avatar
    Join Date
    Jul 2003
    Location
    I'm a Jessie
    Posts
    35,157
    Thanks
    3,105
    Thanked
    3,138 times in 1,916 posts
    • Zak33's system
      • Storage:
      • Kingston HyperX SSD, Hitachi 1Tb
      • Graphics card(s):
      • Nvidia 1050
      • PSU:
      • Coolermaster 800w
      • Case:
      • Silverstone Fortress FT01
      • Operating System:
      • Win10
      • Internet:
      • Zen FTC uber speedy
    Quote Originally Posted by badass
    You cant click keep state on the allow outgoing - it just forgets it.
    I can help

    yup..I can

    I had that too.....its the browser you're using !

    Are you using Firefox? If so it doesnt activate the HTML style interface built into the router!

    If youre using IE, then hit Cntrl F5.

    I was trying to get Port Throttling to work for DAYS

    It would NOT activate it just ignored me clicking the tick boxes.

    I emailed them and the reply was ultra useful. They told me what to try (Cntrl F5 in IE) and I did.

    It worked I stopped using Firefox in the control panel at all.

    Job....is....a.....good'un

    Hope it helps man.

    Cos my Draytek ROCKS

    Quote Originally Posted by Advice Trinity by Knoxville
    "The second you aren't paying attention to the tool you're using, it will take your fingers from you. It does not know sympathy." |
    "If you don't gaffer it, it will gaffer you" | "Belt and braces"

  14. #14
    Senior Member
    Join Date
    Mar 2005
    Posts
    4,826
    Thanks
    161
    Thanked
    358 times in 288 posts
    • badass's system
      • Motherboard:
      • ASUS P8Z77-m pro
      • CPU:
      • Core i5 3570K
      • Memory:
      • 32GB
      • Storage:
      • 1TB Samsung 850 EVO, 2TB WD Green
      • Graphics card(s):
      • Radeon RX 580
      • PSU:
      • Corsair HX520W
      • Case:
      • Silverstone SG02-F
      • Operating System:
      • Windows 10 X64
      • Monitor(s):
      • Del U2311, LG226WTQ
      • Internet:
      • 80/20 FTTC
    Quote Originally Posted by Zak33
    I can help

    yup..I can

    I had that too.....its the browser you're using !

    Are you using Firefox? If so it doesnt activate the HTML style interface built into the router!

    If youre using IE, then hit Cntrl F5.

    I was trying to get Port Throttling to work for DAYS

    It would NOT activate it just ignored me clicking the tick boxes.

    I emailed them and the reply was ultra useful. They told me what to try (Cntrl F5 in IE) and I did.

    It worked I stopped using Firefox in the control panel at all.

    Job....is....a.....good'un

    Hope it helps man.

    Cos my Draytek ROCKS
    Genius
    Thats why it worked sometimes and not others! Fecking firefox!
    "In a perfect world... spammers would get caught, go to jail, and share a cell with many men who have enlarged their penises, taken Viagra and are looking for a new relationship."

  15. #15
    Administrator Moby-Dick's Avatar
    Join Date
    Jul 2003
    Location
    There's no place like ::1 (IPv6 version)
    Posts
    10,665
    Thanks
    53
    Thanked
    385 times in 314 posts
    nice one Zakky
    my Virtualisation Blog http://jfvi.co.uk Virtualisation Podcast http://vsoup.net

  16. #16
    HEXUS.timelord. Zak33's Avatar
    Join Date
    Jul 2003
    Location
    I'm a Jessie
    Posts
    35,157
    Thanks
    3,105
    Thanked
    3,138 times in 1,916 posts
    • Zak33's system
      • Storage:
      • Kingston HyperX SSD, Hitachi 1Tb
      • Graphics card(s):
      • Nvidia 1050
      • PSU:
      • Coolermaster 800w
      • Case:
      • Silverstone Fortress FT01
      • Operating System:
      • Win10
      • Internet:
      • Zen FTC uber speedy
    /takes a bow

    Quote Originally Posted by Advice Trinity by Knoxville
    "The second you aren't paying attention to the tool you're using, it will take your fingers from you. It does not know sympathy." |
    "If you don't gaffer it, it will gaffer you" | "Belt and braces"

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Similar Threads

  1. I need a Draytek!
    By uchiha_itachi in forum SHOPPING AND CLASSIFIEDS
    Replies: 2
    Last Post: 10-10-2005, 05:18 PM
  2. Wireless Routers
    By Zyte in forum Networking and Broadband
    Replies: 20
    Last Post: 16-08-2005, 11:22 PM
  3. Wireless routers question
    By Swafe in forum Networking and Broadband
    Replies: 6
    Last Post: 28-06-2005, 02:47 PM
  4. Wireless routers - inherently unstable?
    By DaBeeeenster in forum Networking and Broadband
    Replies: 13
    Last Post: 15-06-2005, 12:21 PM
  5. usb modem routers
    By ajbrun in forum Networking and Broadband
    Replies: 14
    Last Post: 09-10-2004, 04:29 PM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •