I.ve allowed acces to a server on my home network by dstnat because VPN is not easy for my family to share NAS media (I know is safer with VPN).
Is there any way to control this open port connection? How can I add to blacklist IP´s who attack in this port?
In that case it’s not possible to create a whitelist.
Another possibility is to implement port knocking. This way one opens access to protected service from anonymous remote IP address if that person knows “how to knock on doors”. I’ve heard there are useful apps (for client side) for all favourite OSes (including smart phones).