--- title: "Restrict or deactivate IP Filter (Firewall) Rules - IT Security" slug: "it-security-hardening-restrict-or-deactivate-ip-filter-firewall-rules-en" updated: 2024-07-18T13:17:57Z published: 2024-07-18T13:17:57Z canonical: "docs.insys-icom.com/it-security-hardening-restrict-or-deactivate-ip-filter-firewall-rules-en" --- > ## Documentation Index > Fetch the complete documentation index at: https://docs.insys-icom.com/llms.txt > Use this file to discover all available pages before exploring further. # Restrict or deactivate IP Filter (Firewall) Rules - IT Security IP filter rules (exceptions for filtering the IP packets) are already added in default settings. Further filter rules can be added by the wizards automatically. It is recommended to check these already existing filter rules for utmost security. If existing filter rules are not necessary, these should be deactivated. If existing filter rules are not necessary in their full extent, these should be restricted. If only IPv4 or IPv6 is used, all existing filter rules are to be limited to the IP version used - this blocks IP traffic for the IP version that is not used. ## Deactivate or delete filter rules 1. Click in the ![lan](https://docs.insys-icom.de/assets/icons/lan.png) *Network* → *Firewall / NAT* menu in the line of the desired filter rule on ![pencil](https://docs.insys-icom.de/assets/icons/pencil.png) to modify it. 2. If this filter rule is temporarily not required, uncheck the checkbox *active*. 3. If this filter rule is permanently not required, click on ![delete](https://docs.insys-icom.de/assets/icons/delete.png). 4. Click on **SUBMIT** . 5. Click on **ACTIVATE PROFILE** **![cog white](https://docs.insys-icom.de/assets/icons/cog_white.png)** . ## Restrict filter rules 1. Click in the ![lan](https://docs.insys-icom.de/assets/icons/lan.png) *Network* → *Firewall / NAT* menu in the line of the desired filter rule on ![pencil](https://docs.insys-icom.de/assets/icons/pencil.png) to modify it. 2. Select the *IP version*, if the rule shall only permit IP packets of a certain version. 3. Check under *Input interface* only the interface over which the packet is allowed to reach the router. 4. Check under *Output interface* only the interface over which the packet is allowed to leave the router. 5. If the filter rule is supposed to permit only IP packets of a certain IP address and/or a certain port, enter these under *Source IP address* or *Source port*. 6. If the filter rule is supposed to permit only IP packets to a certain IP address and/or a certain port, enter these under *Destination IP address* or *Destination port*. 7. Click on **SUBMIT** . 8. Click on **ACTIVATE PROFILE** **![cog white](https://docs.insys-icom.de/assets/icons/cog_white.png)** . > [!NOTE] > Please note! > > Many applications assign the source port dynamically which does not allow to restrict to a certain port or only to a port range. The existing filter rule for HTTPS access to the web Interface has been limited to **IPv4** and the source address **192.168.1.7** in the following example. ![itsec en ip filter edit 01](https://docs.insys-icom.de/itsec/assets/itsec_en_ip_filter_edit_01.png) I