Syntax to block TCP/UDP port 135-139 on D-Link NAT?


Nancy Lebovitz

All I want to do is block ports 137-139 & 445 on Windows XP SP2.
But I ended up blocking EVERYTHING and screwing it all up.
Can you tell me what I did wrong (or what to do right)?

I have a home network with a single wireless WinXP computer.
My NAT is a D-Link 2.4 Ghz Wireless Router.
I ran the steps below but it blocked all network traffic somehow???
What did I do wrong to block ports 137-139 & 445???

I first tried the D-Link "Help" button but all it said was:
"Firewall Rules is an advance feature used to deny or allow traffic from
passing through the device. It works in the same way as IP Filters with
additional settings. You can create more detailed rules for the device."

Uh, That didn't help me very much (I need an example) so I tried to set
things myself but I don't know if I did it right because I had to unset it
all just to get out to google on my browser afterward.

My first question is should I set up "IP Filters" or "Firewall Rules". I
didn't know so I went arbitrarily to "Firewall Rules" because "IP Filters"
seemed to be outbound from the LAN to the WAN while "Firewall Rules" seemed
to go both ways.

Here is what I did to block (I think) ports 135-139 & 445 on Firewall Rules
on the DLINK NAT.
1) I logged into as "admin".
2) I selected the "Advanced" tab & "Firewall" button.
3) I set the two "Firewall rules" sections as shown below.

The first "Firewall Rules" section asks for a name (what name does it
want?) so I left it blank not knowing what name it wanted but I did hit the
disable radio dial (not knowing what else to do in this first section).
( )Enabled (o)disabled
Name = <currently this is blank>

Here is how I set the second "Firewall Rules" section:
Action ( )Allow (o)Deny
Source Interface = LAN, WAN, or * (I chose *)
Source IP Range Start = <blank> (I put in
Source IP Range End = <blank> (I put in
Destination Interface = LAN, WAN, or * (I chose *)
Destination IP Range Start = <blank> (I put in
Destination IP Range End = <blank> (I put in
Destination Protocol = TCP, UDP, ICMP, or * (I chose *)
Destination Port Range = 137 - 129
Schedule (o)Always

I did likewise for port 445.

What did I do wrong?
I had to reset the NAT just to get this message out as everything is




Allow Allow to Ping WAN port WAN,* LAN, ICMP,8
Deny Default source =*,* destination=LAN,* protocol= *,*
Allow Default LAN,* *,* *,*

By default dlink routers block all traffic from *,* (all) to the LAN

For the soruce and destination: The * can be WAN, LAN or * (any)
For the protocol: The * can be the name of the protocol and the second after
the comma can be a port or range of ports.

The Firewall rules control traffic between the lan and wan. Unless you
punch a hole, all incomming requests are denied. All outgoing requests are
allowed. By default inbound traffic to 137-139 and 445 is denied.

Your biggest worry is on the lan (wireless) side. All traffic is allowed by
default. The easiest way to manage that is to use MAC filters. They control
all lan access. Then enable your windows firewall to protect against
computers on your own lan.

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question