Default Security Policy
Chapter 12: Setting Your Security Policy
233
What should be the event logging policy?
Which Quality of Service (QoS) classes will you need?
Default Security Policy
The Nokia IP60 default security policy includes the following rules:
Access is blocked from the WAN (Internet) to all internal networks (LAN, DMZ, primary
WLAN, VLANs, VAPs, and OfficeMode).
Access is allowed from the internal networks to the WAN, according to the firewall security level
(Low/Medium/High).
Access is allowed from the LAN network to the other internal networks (DMZ, primary WLAN,
VLANs, VAPs, and OfficeMode).
Access is blocked from the DMZ, primary WLAN, VLAN, VAP, and OfficeMode networks to
the other internal networks, (including between different VLANs and VAPs).
HTTPS access to the Nokia IP60 Portal (my.firewall, my.hotspot, and my.vpn) is allowed from
all internal networks.
HTTP access to the Nokia IP60 Portal (my.firewall, my.hotspot, and my.vpn) is allowed from all
internal networks except the WLAN and VAPs. You can allow HTTP access from the primary
WLAN and VAPs by creating a specific user-defined firewall rule.
When using the print server function (see
Using Network Printers
on page 457), access from
internal networks to connected network printers is allowed.
Access from the WAN to network printers is blocked.
These rules are independent of the firewall security level.
You can easily override the default security policy, by creating user-defined firewall rules. For further
information, see
Using Rules
on page 238.
Setting the Firewall Security Level
The firewall security level can be controlled using a simple lever available on the
Firewall
page. You can set
the lever to the following states.
Summary of Contents for IP60 - Security Appliance
Page 1: ...Part No N450000643 Rev 001 Published February 2008 Nokia IP60 Security Appliance User Guide ...
Page 4: ...4 Nokia IP60 Security Appliance User Guide ...
Page 10: ......
Page 12: ......
Page 38: ......
Page 58: ......
Page 108: ......
Page 268: ......
Page 482: ......