Firewall rules and online gaming in USG flex 200

mat17
mat17 Posts: 45  Freshman Member
First Comment Friend Collector Fourth Anniversary
edited February 2023 in Security

Hello,

I have a gaming console which requires to access a custom service.

So I'have created a rule which allows accessing this custom service. But the gaming console also send UDP packets from this service port to the other players. And they are blocked by the firewall.

How can I allow this traffic?

Thanks in advance

All Replies

  • PeterUK
    PeterUK Posts: 3,459  Guru Member
    100 Answers 2500 Comments Friend Collector Seventh Anniversary
    edited February 2023

    Do you have the default LAN to WAN all services outgoing? Or are you wanting to limit what goes out by rules?

    Games can be tricky to allow some games like Rocket League say this port range but they unofficially do not stick to that, and some games are random and some can be worked around depending on UDP traversal.

    So whats the game?

    One port you need to NAT/Virtual Server incoming is UDP 3659

    Look in your logs to find the blocked traffic and enable other parts of the logs for more info

  • mat17
    mat17 Posts: 45  Freshman Member
    First Comment Friend Collector Fourth Anniversary

    Hello,

    No, I do not allow all outgoing traffic: everything except what have been allowed is blocked.

    The game is Crash Team Racing on PS4.

    The service used by this game is TCP/UDP 3074.

    I've created a rule to allow access to a server of this kind, and it works. But I can't find the way to define a way to define a rule with this port source.

    I don't need others players being able to access my PS4, I need to allow my PS4 to contact others players.

    Kind regards

  • mMontana
    mMontana Posts: 1,389  Guru Member
    50 Answers 1000 Comments Friend Collector Fifth Anniversary

    From

    your PS4 address, any port

    to

    any wan address, custom service port

    Allow

  • mat17
    mat17 Posts: 45  Freshman Member
    First Comment Friend Collector Fourth Anniversary

    Hello,

    No, the packets are not like that.

    What I need is:

    From PS4 address, custom service port, to any WAN address, any port.

    Indeed, I could use the following workaround:

    From PS4 address, any port to any WAN address any port,

    But I was expecting something more secure.

    Kind regards

  • PeterUK
    PeterUK Posts: 3,459  Guru Member
    100 Answers 2500 Comments Friend Collector Seventh Anniversary

    You need to look in logs and work out what needs to be allowed

  • Zyxel_Stanley
    Zyxel_Stanley Posts: 1,377  Zyxel Employee
    100 Answers 1000 Comments Friend Collector Seventh Anniversary

    Hi @mat17

    You may refer to this website. It looks port forwarding rules is required.

  • mat17
    mat17 Posts: 45  Freshman Member
    First Comment Friend Collector Fourth Anniversary

    Hello @Zyxel_Stanley

    I had missing ports.

    I created the related rules. Will see if it allows the expected trafic.

    Thanks

Security Highlight