McAfee UTM Firewall 4.0.4 Administration Guide
151
Firewall menu options
Firewall overview
Incoming Access – Packets destined for the appliance (Inputs) are processed by Incoming Access rules.
See
Incoming access
.
Access Control – All other packets travelling through the appliance (Forwards) that are not blocked by
packet filtering are turned over to access control. For details, see
Access control
.
Note:
Web list, content filtering, antivirus and antispam use proxies. When these options are enabled, the forward
packet filter rules do not apply. Access control functions are performed by the proxy. See
Web Lists tab
,
McAfee
Web Gateway web filtering service
,
Antivirus
, and
Antispam (TrustedSource)
for more details.
IPS – If IPS is enabled, packets pass to IPS after handling by Access Control mechanisms. For details, see
Intrusion Detection Systems
.
Source NAT – If Source NAT is enabled, the UTM Firewall device replaces the source IP address of a
packet with another IP address, such as hiding your private network behind the public address of the UTM
Firewall unit. See
About masquerading and source NAT
.
Firewall overview
The UTM Firewall appliance is equipped with a fully-featured firewall. The firewall allows you to control both
incoming and outgoing access so that PCs on local networks can have tailored Internet access facilities
while being shielded from malicious attacks from external networks. The stateful firewall of the appliance
keeps track of outgoing connections, such as a PC on your LAN requesting content from a server on the
Internet, and only allows corresponding incoming traffic, such as the server on the Internet sending the
requested content to the PC. By default, your appliance allows network traffic as shown in
Table 11
.
Sometimes it is useful to allow some incoming connections; for example, if you have a mail or Web server
on your LAN or DMZ that you want to be accessible from the Internet. This is accomplished using a
combination of NAT and packet filter rules. The Management Console provides a powerful interface for
tailoring the firewall to your network.
The Firewall menu contains the following topics for its menu options (some models do not have all menu
options):
•
Definitions
•
Packet filtering
•
NAT
•
Connection tracking
•
Intrusion Detection Systems
•
Access control
•
Antivirus
•
Antispam (TrustedSource)
Table 11 Default network traffic
Incoming Interface
Outgoing Interface
Action
LAN
Any
Accept
VPN
Any
Accept
Dial-in
Any
Accept
DMZ
Internet
Accept
DMZ
Any except Internet
Drop
Internet
Any
Drop
Guest
Any
Drop
Summary of Contents for SG310
Page 1: ...McAfee UTM Firewall Administration Guide version 4 0 4...
Page 10: ...10 McAfee UTM Firewall 4 0 4 Administration Guide...
Page 148: ...148 McAfee UTM Firewall 4 0 4 Administration Guide Network Setup menu options SIP...
Page 372: ...372 McAfee UTM Firewall 4 0 4 Administration Guide System menu features Advanced menu...
Page 410: ...410 McAfee UTM Firewall 4 0 4 Administration Guide Index...
Page 411: ......
Page 412: ...700 2237A00...