Hello Everybody,
For advanced security packet inspection, i was wondering if it is possible to add some cool conditions for port forwarding.
I Explain myself, when you forward ports for Wan to Lan (or from internet to internal lan), the astaro firewall forwads the incoming tcp connection on External Wan Adress and forwards it to your internal lan host.
The problem is even if the internal host is down or the service running on the internal host is down, the packet are forwarded through if your DNAT rule is still activated with you incoming Filter rule.
if the internal machine is down, astaro firewall just forwads packets to it, but if the internal service is down, the internal host may respond by an icmp port unreacheable to the outside world, showing everybody you have an open port
Is it possible to make astaro drop incoming tcp connections if in a in rule the internal host machine or service is unreacheable (due to power off, or service down) ?
This thread was automatically locked due to age.