• Configuration Advice On The Firewall Of A TP-Link ER605 Gigabit VPN Router

    Home » Forums » Networking – routers, firewalls, network configuration » Configuration Advice On The Firewall Of A TP-Link ER605 Gigabit VPN Router

    Author
    Topic
    #2439051

    Right out’ta the box the TP-Link ER605 Gigabit VPN, load-balancing wired (only) router is on-line, in stand-alone mode. I’m out of the habit of knowing which default firewall rules to leave alone or configure. Do any of you Ask Woody regulars have a checklist of rules you like which you could share? Thank you.

    The ER605’s main porpoise is to be a decent, configurable, 2nd, SPI firewall for the network’s wired internet WAN signal, which comes through a Comcast XP6 router gateway.

    Here is the cover of its datasheet. router

    I’m doing this so I can put the the XP6 on bridge mode. I’m putting it into bridge mode because it shuts off the XP6’s WiFi, which is desired by the human client. When the XP6 is in bridge mode, its control panel shows its firewall is still active.

    Here’s the full datasheet for this ER605, which has hardware version 1.0, and firmware version 1.1.1 Build 20210723, Rel.64608. I notice that IPv6 is available for later hardware versions so I’ll ask TP-Link if the more recent versions of the router have that.

    Human, who sports only naturally-occurring DNA ~ oneironaut ~ broadcaster

    • This topic was modified 3 years, 1 month ago by Mr. Austin.
    • This topic was modified 3 years, 1 month ago by Mr. Austin.
    • This topic was modified 3 years, 1 month ago by Mr. Austin.
    Viewing 1 reply thread
    Author
    Replies
    • #2439176

      When I install a new router, I generally visit GRC | ShieldsUP! — Internet Vulnerability Profiling. That gives me a good starting point to see what might need to be adjusted.

      --Joe

      • #2439181

        Good idea, thanks. When I use a commercial VPN, Gibson’s testing shows the IP is OK. Without the VPN it exposes the ISP’s name and IPv6.

        Human, who sports only naturally-occurring DNA ~ oneironaut ~ broadcaster

    • #2439330

      Knowing the ISP name and V6 address is not a security risk.
      Having open ports is.

      cheers, Paul

    Viewing 1 reply thread
    Reply To: Configuration Advice On The Firewall Of A TP-Link ER605 Gigabit VPN Router

    You can use BBCodes to format your content.
    Your account can't use all available BBCodes, they will be stripped before saving.

    Your information: