Chapter 8: Configuring Filtered Services
132
WatchGuard Firebox System
The following order is used:
IP refers to exactly one host IP address
List refers to multiple host IP addresses, a network address, or
an alias
Any refers to the special “Any” target (not “Any” services)
When two icons are representing the same service (for
example, two Telnet icons or two Any icons), they are
sorted using the above tables. The most specific one will
always be checked first for a match. If a match is not made,
the next specific service will be checked, and so on, until
either a match is made or no services are left to check. In
the latter case, the packet is denied. For example, if there
are two Telnet icons, telnet_1 allowing from A to B and
telnet_2 allowing from C to D, a Telnet attempt from C to E
will first check telnet_1, and then telnet_2. Because no
match is found, the rest of the rules are considered. If an
outgoing service allows from C to E, it will do so.
When only one icon is representing a service in a prece-
dence category, only that service is checked for a match. If
the packet matches the service and both targets, the service
rule applies. If the packet matches the service but fails to
match either target, the packet is denied. For example, if
one Telnet icon allows from A to B, a Telnet attempt from A
to C will be blocked without considering any services fur-
From
To
Rank
IP
IP
0
List
IP
1
IP
List
2
List
List
3
Any
IP
4
IP
Any
5
Any
List
6
List
Any
7
Any
Any
8
Summary of Contents for Firebox X10E
Page 1: ...WatchGuard Firebox System User Guide WatchGuard Firebox System ...
Page 12: ...xii WatchGuard Firebox System ...
Page 44: ...Chapter 2 Service and Support 22 WatchGuard Firebox System ...
Page 61: ...Cabling the Firebox User Guide 39 ...
Page 68: ...Chapter 3 Getting Started 46 WatchGuard Firebox System ...
Page 78: ...Chapter 4 Firebox Basics 56 WatchGuard Firebox System ...
Page 156: ...Chapter 8 Configuring Filtered Services 134 WatchGuard Firebox System ...
Page 182: ...Chapter 9 Configuring Proxied Services 160 WatchGuard Firebox System ...
Page 220: ...Chapter 11 Intrusion Detection and Prevention 198 WatchGuard Firebox System ...
Page 242: ...Chapter 12 Setting Up Logging and Notification 220 WatchGuard Firebox System ...
Page 256: ...Chapter 13 Reviewing and Working with Log Files 234 WatchGuard Firebox System ...
Page 274: ...Chapter 14 Generating Reports of Network Activity 252 WatchGuard Firebox System ...