ProSafe Wireless-N VPN Firewall SRXN3205 Reference Manual
5-28
Firewall Security and Content Filtering
v1.0, July 2008
Enabling Port Triggering
Port triggering allows some applications running on a LAN network to be available to external
applications that would otherwise be partially blocked by the firewall. Using this feature requires
the port numbers used by the application.
Once configured, port triggering operates as follows:
1. A PC makes an outgoing connection using a port number defined in the Port Triggering table.
2. The firewall records this connection, opens the additional INCOMING port or ports associated
with this entry in the Port Triggering table, and associates them with the PC.
3. The remote system receives the PC’s request and responds using the different port numbers
that you have now opened.
4. The VPN firewall matches the response to the previous request, and forwards the response to
the PC.
Without Port Triggering, this response would be treated as a new connection request rather than a
response. As such, it would be handled in accordance with the inbound service rules.
Note these restrictions with Port Triggering:
•
Only one PC can use a port triggering application at any time.
•
After a PC has finished using a port triggering application, there is a time-out period before the
application can be used by another PC. This is required because the VPN firewall cannot be
sure when the application has terminated.
To add a port triggering rule:
1.
Select
Security
from the main menu and Port Triggering from the submenu.
Note:
For additional ways of allowing inbound traffic, see
“Inbound Rules (Port
Forwarding)” on page 5-4
.