User Manual
Geneko GWR High Speed Router Series
123
Firewall – example
Firewall implemented in GWR-HS routers has numerous options for matching interesting traffic. Traffic flow is
controlled through the router with three actions triggered by firewall:
1.
ACCEPT – traffic is passed through the router without any changes implemented
2.
REJECT – traffic is blocked with ICMP error messages
3.
DROP – traffic is blocked without any error messages, connection is retried until the threshold for
retransmission is exceeded
By default all traffic is PERMITTED. To block all the traffic not defined under stated rules last entry in firewall
table should be DROP ALL.
Rule priority defines order by which router matches inspected packets. After first match between rule and
packet, no other rule is compared against matched traffic.
Firewall has 17 predefined rules for the most common usage. These 17 rules are following:
1.
Allow ALL from local LAN
All traffic originating from local subnet is allowed to access router Ethernet interface. It is important to keep this
rule enabled to prevent losing local management interface.
2.
Allow already established traffic
For inbound TCP only. Allows TCP traffic to pass if the packet is a response to an outbound-initiated session.
3.
Allow TELNET on ppp_0
Accepts telnet connection from the outside to router’s WAN interface, for management over CLI interface
4.
Allow HTTP on ppp_0
Accepts WEB traffic from the outside to router’s WAN interface, for management over WEB interface
5.
Allow PING on ppp_0-with DDoS filter
ICMP traffic to WAN interface of the router is allowed with prevention of Distributed Denial-of-service attack
Allow RIP protocol
6.
Allow RIP on ppp_0
7.
Allo RIP on ppp_0 – route
Allow GRE protocol
8.
Allow GRE tunnels on ppp_0
9.
Allow GRE Keepalive on ppp_0
Allow IPSec protocol
10.
Allow IPSec tunnels on ppp_0 – protocol
11.
Allow IPSec tunnels on ppp_0 – IKE
12.
Allow IPSec tunnel on ppp_0 – IKE_NATt
Allow OpenVPN protocol
13.
Allow OpenVPN tunnels on ppp_0 – UDP
14.
Allow OpenVPN tunnels on ppp_0 – TCP
15. Allow SNMP on ppp_0
SNMP requests are allowed to be sent to the router over WAN interface
16.
Allow MODBUS on ppp_0
MODBUS conversion over default port UDP 502 is permitted
17.
REJECT all other traffic
All packets which are not stated as ACCEPT in previous rules are denied. If this rule is not enabled all
packets which are not stated as DROP/REJECT are permitted.
Summary of Contents for GWR High Speed Router Series
Page 1: ...GWR High Speed Cellular Router Series User Manual version 1 1 Date June 2014...
Page 26: ...User Manual Geneko GWR High Speed Router Series 26 Figure 17 DHCP Server configuration page...
Page 61: ...User Manual Geneko GWR High Speed Router Series 61 Figure 38 Modbus gateway configuration page...