Actions
Feature #6776
openAllow disabling of "filter rule association" by default
Status:
New
Priority:
Normal
Assignee:
-
Category:
Rules / NAT
Target version:
-
Start date:
09/07/2016
Due date:
% Done:
0%
Estimated time:
Plus Target Version:
Release Notes:
Description
This setting is inherently insecure, as it opens a hole in your firewall for the world to get into. Fine for public-facing servers or home users, but not so great when you need remote access from a limited number of IP addresses. Of course it can be disabled when the rule is created, but it's easy to overlook.
I would like to see the ability to set a system-wide default, similar to the "NAT reflection" setting above it, so that this can be globally disabled for those who want to maintain some semblance of security over their WAN port.
Actions