14.3 Services
195
•
Any
— all the ports available (
1-65535
)
•
Equal to
—a particular port (e.g.
80
)
•
Greater than
,
Less than
— all ports with a number that is either greater or less
than the number defined
•
Not equal to
— all ports that are not equal to the one defined
•
In range
— all ports that fit to the range defined (including the initial and the
terminal ones)
•
List
— list of the ports divided by commas (e.g.
80,8000,8080
)
Protocol Inspectors
WinRoute
includes special plug-ins that monitor all traffic using application protocols, such as
HTTP, FTP or others. The modules can be used to modify (filter) the communication or adapt
the firewall’s behavior according to the protocol type. Benefits of protocol inspectors can be
better understood through the two following examples:
1.
HTTP protocol inspector
monitors traffic between clients (browsers) and Web servers. It
can be used to block connections to particular pages or downloads of particular objects
(i.e. images, pop-ups, etc.).
2.
With active FTP, the server opens a data connection to the client. Under certain conditions
this connection type cannot be made through firewalls, therefore FTP can only be used
in passive mode. The
FTP protocol inspector
distinguishes that the FTP is active, opens
the appropriate port and redirects the connection to the appropriate client in the local
network. Due to this fact, users in the local network are not limited by the firewall and
they can use both FTP modes (active/passive).
The protocol inspector is enabled if it is set in the service definition and if the correspond-
ing traffic is allowed. Each protocol inspector applies to a specific protocol and service. In
the default
WinRoute
configuration, all available protocol inspectors are used in definitions
of corresponding services (so they will be applied to corresponding traffic automatically), ex-
cept protocol inspectors for
SIP
and
H.323
(
SIP
and
H.323
are complex protocols and protocol
inspectors may work incorrectly in some configurations).
To apply a protocol inspector explicitly to another traffic, it is necessary to define a new service
where this inspector will be used or to set the protocol inspector directly in the corresponding
traffic rule.
Example
You want to perform inspection of the HTTP protocol at port
8080
. Define a new service:
TCP
protocol, port
8080
,
HTTP
protocol inspector. This ensures that
HTTP
protocol inspector will
be automatically applied to any
TCP
traffic at port
8080
and passing through
WinRoute
.
Summary of Contents for Firewall6
Page 1: ...Kerio WinRoute Firewall 6 Administrator s Guide Kerio Technologies...
Page 129: ...8 5 HTTP cache 129...
Page 404: ...404...