ER605 whitelisting so only certain external IP addresses can get thru port forwarding
I am trying to set things up so that traffic (UDP audio streams) can pass through specific ports on a ER605 (in standalone mode, we do not use Omada Controllers here), via port-forwarding, but only if they're coming from a specific static IP address of a WAN port on another ER605 at a different location. Basically, I'm trying to set up a whitelist.
This seems like it shouldn't be that hard, yet I cannot figure out how to do it? I tried setting up rules in Firewall > Access Control, but there's no way to have a rule that says "block everything EXCEPT..." I don't know if the ER605 applies those Access Control rules sequentially but my experiments with them seem to indicate it does not in any reliable way. Sometimes it blocks it, sometimes it doesn't.
What I am I missing here?

