P-660H/HW-T Series User’ Guide
133
Chapter 11 Firewall Configuration
Note:
If you configure firewall rules without a good understanding of how they work,
you might inadvertently introduce security risks to the firewall and to the
protected network. Make sure you test your rules after you configure them.
For example, you may create rules to:
• Block certain types of traffic, such as IRC (Internet Relay Chat), from the LAN to the
Internet.
• Allow certain types of traffic, such as Lotus Notes database synchronization, from
specific hosts on the Internet to specific hosts on the LAN.
• Allow everyone except your competitors to access a Web server.
• Restrict use of certain protocols, such as Telnet, to authorized users on the LAN.
These custom rules work by comparing the Source IP address, Destination IP address and IP
protocol type of network traffic to rules set by the administrator. Your customized rules take
precedence and override the Prestige’s default rules.
11.3 Rule Logic Overview
Note:
Study these points carefully before configuring rules.
11.3.1 Rule Checklist
State the intent of the rule. For example, “This restricts all IRC access from the LAN to the
Internet.” Or, “This allows a remote Lotus Notes server to synchronize over the Internet to an
inside Notes server.”
1
Is the intent of the rule to forward or block traffic?
2
What direction of traffic does the rule apply to?
3
What IP services will be affected?
4
What computers on the LAN are to be affected (if any)?
5
What computers on the Internet will be affected? The more specific, the better. For
example, if traffic is being allowed from the Internet to the LAN, it is better to allow only
certain machines on the Internet to access the LAN.
11.3.2 Security Ramifications
1
Once the logic of the rule has been defined, it is critical to consider the security
ramifications created by the rule:
2
Does this rule stop LAN users from accessing critical resources on the Internet? For
example, if IRC is blocked, are there users that require this service?
3
Is it possible to modify the rule to be more specific? For example, if IRC is blocked for all
users, will a rule that blocks just certain users be more effective?
Summary of Contents for P-660H Series
Page 2: ......
Page 10: ...P 660H HW T Series User Guide 9 Customer Support ...
Page 32: ...P 660H HW T Series User Guide 31 List of Figures ...
Page 38: ...P 660H HW T Series User Guide 37 List of Tables ...
Page 42: ...P 660H HW T Series User Guide 41 Introduction to DSL ...
Page 62: ...P 660H HW T Series User Guide 61 Chapter 3 Wizard Setup for Internet Access ...
Page 90: ...P 660H HW T Series User Guide 89 Chapter 5 Wireless LAN ...
Page 132: ...P 660H HW T Series User Guide 131 Chapter 10 Firewalls ...
Page 162: ...P 660H HW T Series User Guide 161 Chapter 13 Remote Management Configuration ...
Page 176: ...P 660H HW T Series User Guide 175 Chapter 14 Universal Plug and Play UPnP ...
Page 182: ...P 660H HW T Series User Guide 181 Chapter 15 Logs Screens ...
Page 196: ...P 660H HW T Series User Guide 195 Chapter 16 Media Bandwidth Management Advanced Setup ...
Page 208: ...P 660H HW T Series User Guide 207 Chapter 17 Maintenance ...
Page 218: ...P 660H HW T Series User Guide 217 Chapter 19 Menu 1 General Setup ...
Page 222: ...P 660H HW T Series User Guide 221 Chapter 20 Menu 2 WAN Backup Setup ...
Page 226: ...P 660H HW T Series User Guide 225 Chapter 21 Menu 3 LAN Setup ...
Page 230: ...P 660H HW T Series User Guide 229 Chapter 22 Wireless LAN Setup ...
Page 236: ...P 660H HW T Series User Guide 235 Chapter 23 Internet Access ...
Page 250: ...P 660H HW T Series User Guide 249 Chapter 25 Static Route Setup ...
Page 254: ...P 660H HW T Series User Guide 253 Chapter 26 Bridging Setup ...
Page 270: ...P 660H HW T Series User Guide 269 Chapter 27 Network Address Translation NAT ...
Page 286: ...P 660H HW T Series User Guide 285 Chapter 29 Filter Configuration ...
Page 306: ...P 660H HW T Series User Guide 305 Chapter 32 System Information and Diagnosis ...
Page 318: ...P 660H HW T Series User Guide 317 Chapter 33 Firmware and Configuration File Maintenance ...
Page 324: ...P 660H HW T Series User Guide 323 Chapter 34 System Maintenance ...
Page 328: ...P 660H HW T Series User Guide 327 Chapter 35 Remote Management ...
Page 338: ...P 660H HW T Series User Guide 337 Chapter 36 IP Policy Routing ...
Page 342: ...P 660H HW T Series User Guide 341 Chapter 37 Call Scheduling ...
Page 358: ...P 660H HW T Series User Guide 357 Appendix A ...
Page 360: ...P 660H HW T Series User Guide 359 Appendix B ...
Page 384: ...P 660H HW T Series User Guide 383 Appendix D ...
Page 388: ...P 660H HW T Series User Guide 387 Appendix F ...
Page 394: ...P 660H HW T Series User Guide 393 Appendix G ...
Page 398: ...P 660H HW T Series User Guide 397 Appendix H ...
Page 401: ...P 660H HW T Series User Guide Appendix I 400 ...
Page 402: ...P 660H HW T Series User Guide 401 Appendix I ...
Page 456: ...P 660H HW T Series User Guide 455 Appendix M ...