Hi,
i need to configure a system where devices on the LAN site should have only limited access to the WAN site - lets say only samba to some specific server in the WAN and nothing else.
For security reasons people should use only defined services on specific devices on the LAN
How to manage that with Luci?
The most efficient way to do this is to remove the lan > wan forwarding rule in the firewall zone settings, and then create a traffic rule that accepts traffic from the lan to whatever destination you allow (or ports, or protocols, etc.)