    Firewall Rules Explanations

      Hi there,


      My apologies for a post that someone with more firewall knowledge would laugh at, but I need some confirmation that my understanding of what some of the default rules do is correct.


      First, upon an upgrade to v4, I found it necessary to disable the built-in "DropDNS" rule, as our internal DNS server could not make any queries to external servers. I presume that I could have directed it to the LAN interface and used the DNS proxy feature of the router, but I did not. This was a bit of a "Gotcha" because this rule did not exist in v3.x. Is there a better way to handle this?


      Also, what do the rules "Drop local traffic to Internet" and "Drop local traffic from Internet" accomplish?