Stateful ACL's

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.

Stateful ACL's

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.
Stateful ACL's
Stateful ACL's
2025-02-24 19:41:20 - last edited 2025-04-21 06:29:54
Model: ER7206 (TL-ER7206)  
Hardware Version: V2
Firmware Version: 2.1.2

Hello,

 

Is there a way to configure  an ACL on the router (ER7206 v2 in Standalone Mode) to allow outgoing and deny incoming except related or established traffic?  

 

By incoming, i mean traffic coming into the WAN interface from the Internet.  The router does have an active firewall but i am curious if additional stateful ACL rules could be applied on the WAN link to restrict incoming traffic. 

 

Would setting a BLOCK policy using the NEW state acheive this? I'm guessing it would but i want to be sure that the router interprets it this way. 

 

I've also seen a recommendation to use the default auto type for the state but that option isn't available. The available states are New, Established, Related and Invalid. 

 

 

  0      
  0      
#1
Options
1 Accepted Solution
Re:Stateful ACL's-Solution
2025-02-25 01:15:40 - last edited 2025-04-21 06:29:54

Hi @Lees0n 

Thanks for posting in our business forum.

I think it can do. But I never tested such a scenario. You might try it based on what you described.

As for the router, the outgoing and related incoming direction is clear and it should do as the ACL config.

Recommended Solution
  1  
  1  
#2
Options
1 Reply
Re:Stateful ACL's-Solution
2025-02-25 01:15:40 - last edited 2025-04-21 06:29:54

Hi @Lees0n 

Thanks for posting in our business forum.

I think it can do. But I never tested such a scenario. You might try it based on what you described.

As for the router, the outgoing and related incoming direction is clear and it should do as the ACL config.

Recommended Solution
  1  
  1  
#2
Options