Applying firewall instances to interfaces
After defining firewall instances, you can apply them to interfaces, where the instances act as packet filters. Firewall instances filter
packets in one of the following ways, depending on what direction you specify when you apply the firewall instance:
in: If you apply firewall instances with the in direction, the firewall filters packets entering the interface. These packets can be traversing
the vRouter or be destined for the router.
out: If you apply instances with the out direction, the firewall filters packets leaving the interface. These packets can be traversing the
vRouter or originating on the vRouter.
local: If you apply instances with the local, the firewall filters packets destined for the vRouter. The special interface "lo" can be used to
affect packets received on any interface. Note that these instances are run after any "in" instances that may be on the interface.
You can apply many firewall instances to an interface on each direction. They are applied in the order that they are configured on the
interface and direction.
Interaction between firewall, NAT, and routing
The processing order of the various services that might be configured within the vRouter is one of the most important concepts to
understand when working with firewall functionality. If the processing order of the services is not carefully configured, the results
achieved might not be what you expect.
Traffic flow through firewall, NAT, and routing
The following figure shows how traffic flows through the firewall, NAT, and routing services within the vRouter. Notice the order of firewall
instances, destination Network Address Translation (DNAT), routing decisions, and source Network Address Translation (SNAT).
FIGURE 1 Traffic flow through firewall, NAT, and routing components
Scenario 1: firewall instances applied to inbound traffic
In this scenario, firewall instances are applied to inbound (in) traffic on an interface. Notice that firewall instances are evaluated before
DNAT and routing decisions, and after SNAT.
Firewall Overview
Brocade 5600 vRouter Firewall Configuration Guide
16
53-1004253-01
Summary of Contents for 5600 vRouter
Page 6: ...Brocade 5600 vRouter Firewall Configuration Guide 6 53 1004253 01 ...
Page 10: ...Preface Brocade 5600 vRouter Firewall Configuration Guide 10 53 1004253 01 ...
Page 12: ...About This Guide Brocade 5600 vRouter Firewall Configuration Guide 12 53 1004253 01 ...
Page 20: ...Firewall Overview Brocade 5600 vRouter Firewall Configuration Guide 20 53 1004253 01 ...
Page 100: ...ICMPv6 Types Brocade 5600 vRouter Firewall Configuration Guide 100 53 1004253 01 ...