Firewall Protection
134
NETGEAR ProSAFE VPN Firewall FVS318G v2
Order of Precedence for Rules
As you define a new rule, it is added to a table in a Rules screen as the last item in the list, as
shown in the following figure, which shows the LAN WAN Rules screen for IPv4 as an
example:
Figure 9. Order of preference
For any traffic attempting to pass through the firewall, the packet information is subjected to
the rules in the order shown in the Outbound Services and Inbound Services tables,
beginning at the top and proceeding to the bottom. In some cases, the order of precedence of
two or more rules might be important in determining the disposition of a packet. For example,
you should place the most strict rules at the top (those with the most specific services or
addresses). The
Up
and
Down
table buttons in the Action column allow you to relocate a
defined rule to a new position in the table.
Configure LAN WAN Rules
The default outbound policy is to allow all traffic to the Internet to pass through. Firewall rules
can then be applied to block specific types of traffic from going out from the LAN to the
Internet (outbound). This feature is also referred to as service blocking. You can change the
default policy of Allow Always to Block Always to block all outbound traffic, which then allows
you to enable only specific services to pass through the VPN firewall.
This section contains the following topics:
•
Create LAN WAN Outbound Service Rules
•
Create LAN WAN Inbound Service Rules
To change the default outbound policy for IPv4 traffic or to change existing IPv4 rules:
1.
Log in to the unit: