Chapter 16: Controlling Access to the ER-1000
TR0190 Rev. B1
105
Web GUI
The connection tracking timeout is set with the “Conntrack Connection Timeout” field on the
“Connections” sub-tab on the “Firewall” tab of the “Security” page (see Figure 48). This field is
located under the “Connection Tracking” heading. Specify the timeout limit in seconds.
16.4.3
Limiting Number of TCP Connections Per Client Device
The number of TCP connections allowed per client device can be limited. For most use cases,
setting the connection limit to 30 is sufficient.
Users running file sharing applications may have difficulties establishing connections
when TCP connection limiting is enabled since the file sharing application may be
consuming the maximum number of TCP connections allowed.
CLI
The ‘conntrack.connlimit.enable’ parameter in the ‘firewall’ interface is used to set the state of
TCP connection limiting. The ‘conntrack.connlimit.connections’ parameter is used to set the
maximum number of connections allowed per client device.
>
use firewall
firewall>
set conntrack.connlimit.enable=yes
firewall>
set conntrack.connlimit.connections=30
Web GUI
The TCP connection limit-related settings are set on the “Connections” sub-tab on the
“Firewall” tab of the “Security” page (see Figure 48). The “Conntrack Limiting” drop-down box
sets the state of TCP connection limiting and the “Conntrack Connection Limits” sets the
maximum number of TCP connections allowed per client device.
16.5 Custom Firewall Rules
Custom firewall rules can be added that control how traffic forwarded by an EL-500 is handled.
For example, rules can be added to:
•
Block client traffic on certain ports
•
Block traffic from a given client access interface to a certain subnet
The custom firewall rules can be added on the “Custom Rules” sub-tab on the “Firewall” tab on
the “Security” page as shown in Figure 49. These rules are specified as you would specify
Summary of Contents for EL-500
Page 20: ...Chapter 3 Using the Web Interface TR0190 Rev B1 20 Figure 8 Rebooting the EL 500...
Page 68: ...Chapter 11 Ethernet Interface Configuration TR0190 Rev B1 68 Figure 38 Wired DHCP settings...
Page 108: ...Chapter 16 Controlling Access to the ER 1000 TR0190 Rev B1 108 Figure 50 VAP ACL configuration...