WQ6N
Occasional Visitor
If this has been already vetted, please point me in the correct direction. New to the AC5300 and ASUSWRT-Merlin
I am using the gui Port Forwarding to allow external access to internal DMZ servers. I have also set up iptables INPUT ipset filters to control ingress packets. However, it is apparent that the VSERVER DNAT chains are going direct without filtering on the iptables INPUT ipset filters.
In order for me to make use of the iptables INPUT ipset filters for all ingress packets, do I need to remove the gui VSERVER rules and create FORWARD rules behind the INPUT ipset filters?
Thank you for the assistance.
I am using the gui Port Forwarding to allow external access to internal DMZ servers. I have also set up iptables INPUT ipset filters to control ingress packets. However, it is apparent that the VSERVER DNAT chains are going direct without filtering on the iptables INPUT ipset filters.
In order for me to make use of the iptables INPUT ipset filters for all ingress packets, do I need to remove the gui VSERVER rules and create FORWARD rules behind the INPUT ipset filters?
Thank you for the assistance.