![Moxa Technologies IEF-G9010 Series User Manual Download Page 67](http://html1.mh-extra.com/html/moxa-technologies/ief-g9010-series/ief-g9010-series_user-manual_1841892067.webp)
IEF-G9010 Series User Manual
67
NOTE
If you select
Any
, the policy enforcement rule will apply to traffic from all network interfaces.
5.
In the [Source and Destination Selection] section, configure the following settings:
a.
Select the source and destination IP or IP object profile from the drop-down menu.
i.
Any
ii.
Single IP
iii.
IP Range
iv.
IP Subnet
v.
Object
NOTE
If you select
Object
, you will need to select the IP object from a previously created IP object profile.
6.
In the [Service Object Selection] section, configure the following settings:
a.
Select the Layer 4 criteria from the drop-down menu.
i.
TCP: Specify the port range for this protocol.
ii.
UDP: Specify the port range for this protocol.
iii.
ICMP: Specify the type and code for this protocol.
iv.
Custom: Specify the protocol number for this protocol as defined in the Internet protocol suite.
v.
Service Object
NOTE
If you select
Service Object
, you will need to select the service object from a previously created service
object profile.
7.
In the [Action] section, configure the following settings:
a.
Select the rule action.
i.
Accept: Allow network traffic that matches this rule.
ii.
Deny: Block network traffic that matches this rule.
iii.
Advanced Filter: The node will act based on the selected protocol filter and protocol filter
action.
8.
Click
Save
to save the configuration.
NOTE
Policy enforcement rules in Gateway Mode only work on the network interface level, not on the physical
port level. Policy enforcement rules cannot inspect the traffic between the physical ports under the same
network interface.
Adding Policy Enforcement Rules (For Bridge Mode Only)
Note
Before creating policy enforcement rules, make sure the required objects and profiles are created.
•
IP object profiles
Configuring IP Object Profiles
•
Service object profiles