Private zone firewall templates
Issue 4 May 2005
303
Private zone firewall templates
The private network interface provides connection to the private/corporate LAN. Private zones
are considered trusted networks and because of this most traffic is allowed.
The private high security rules are enforced for both incoming and outgoing packets as follows.
Any incoming traffic from the private zone is allowed except traffic that is destined to the
management zone.
For outgoing traffic to the private zone, traffic initiated from DMZ is strictly denied. All other
traffic is allowed.
OutBoundPublic
AccessVPNKey
Mgmt
Permit
Public-IP
Any
IKE-IN
IKE-AVAYA-IN
Out
Public-IP
Yes
InBoundPublicI
CMP
Permit
Any
Public-IP
ICMPDESTUNREACHAB
LE
ICMPTIMEEXCEEDED
In
Public-IP
No
OutBoundPublic
ICMP
Permit
Public-IP
Any
ICMPDESTUNREACHAB
LE
Out
Public-IP
No
InBoundPublicB
lockAll
Block
Any
Any
Any
In
Public
No
OutBoundPublic
BlockAll
Block
Any
Any
Any
Out
Public
No
Table 33: Public VPN-only firewall rules (continued)
2 of 2
Summary of Contents for 3.7
Page 1: ...VPNmanager Configuration Guide Release 3 7 670 100 600 Issue 4 May 2005...
Page 4: ......
Page 20: ...Preface 20 Avaya VPNmanager Configuration Guide Release 3 7...
Page 32: ...Overview of implementation 32 Avaya VPNmanager Configuration Guide Release 3 7...
Page 53: ...Preferences Issue 4 May 2005 53 Figure 16 Tunnel End Point Policy...
Page 54: ...Using VPNmanager 54 Avaya VPNmanager Configuration Guide Release 3 7...
Page 244: ...Using advanced features 244 Avaya VPNmanager Configuration Guide Release 3 7...
Page 292: ...Upgrading firmware and licenses 292 Avaya VPNmanager Configuration Guide Release 3 7...