D-Link Forums

The Graveyard - Products No Longer Supported => D-Link NetDefend Firewalls => Topic started by: new2d_link on December 26, 2009, 01:37:45 AM

Title: HOW DO I EXCLUDE ONE PC FROM THE FIREWALL PROTECTION
Post by: new2d_link on December 26, 2009, 01:37:45 AM
Hi everyone
I m new to DLINK and I ve recently bought a DFL-210
I managed to connect it to the internet and create the blacklists and whitelists I need, but I can't seem to find how to exclude one or two PCs (IPs) from the protected network.
What I actually need is a way to keep all the static IPs that are set on the company's PCs, so they can still share files and programs, but exclude two ips from the firewall so they can have full unprotected access to the internet.
I tried messing around with the DMZ port but wasn't lucky so far.
Any literature on the subject apart from the manual that came with it?
Thanks
Jim
Title: Re: HOW DO I EXCLUDE ONE PC FROM THE FIREWALL PROTECTION
Post by: Fatman on December 28, 2009, 09:01:24 AM
Create a rule allowing those 2 PCs and place that rule before your rules denying traffic.
Title: Re: HOW DO I EXCLUDE ONE PC FROM THE FIREWALL PROTECTION
Post by: new2d_link on December 28, 2009, 12:19:44 PM
Thanks for the quick reply Fatman.
However I ve already tried that, didn't work. I must be doing something wrong.
Is there any step by step manual for that thing?
I d be obliged if you could lead me to creating that rule.
1.  I created the two addresses in "objects/addressbook/interfaceaddresses
2.  I created an unlimited ALG
3.  created a service that used that ALG
4.  And then I created a rule that used the above and placed it on top of all others.

The problem was that all the other PCs had free access as well.
When I put that rule second then I had limited access same as all the other PCs

So what am I doing wrong?
I could send you the configuration file if you feel like trying.

Thanks anyway
Jim
Title: Re: HOW DO I EXCLUDE ONE PC FROM THE FIREWALL PROTECTION
Post by: Fatman on December 29, 2009, 08:09:01 AM
You know what the config file sounds like the easiest path, this should be a 30 second fix and it sounds like you have given due diligence.  PM me the location that I can download the config from via FTP or HTTP.