@julianstogs-iti I would use the firewall rules to achieve what you want. Remove the relevant forward rule and block everything except the required port. uci show firewall The rules are in /etc/config/firewall