12.1.1 Filter Rules
The default behaviour with Action =
Access
consists of two implicit filter rules: If an in-
coming packet can be assigned to an existing connection and if a suitable connection is ex-
pected (e.g. such as an affiliated connection of an existing connection), the packet is al-
lowed.
The sequence of filter rules in the list is relevant: The filter rules are applied to each packet
in succession until a rule matches. If overlapping occurs, i.e. more than one filter rule
matches a packet, only the first rule is executed. This means that if the first rule denies a
packet, whereas a later rule allows it, the packet is rejected. A deny rule also has no effect
if a relevant packet has previously been allowed by another filter rule.
In the Firewall -> Policies -> Filter Rules menu, a list of all configured filter rules is
shown. Select the show administrative access rules option to display existing filter rules for
administrative access to your device (see System Management -> Administrative Ac-
cess -> Access). These rules can also be edited here.
Fig. 147:
Firewall
->
Policies
->
Filter Rules
You can use the
button to insert another policy above the list entry. The configuration
menu for creating a new policy opens.
You can use the
button to move the list entry. A dialog box opens, in which you can se-
lect the position to which the policy is to be moved.
12 Firewall
Funkwerk Enterprise Communications GmbH
374
bintec R1xxx/R3xxx/R4xxx