
5.8
Advanced Filtering
Advanced filtering is designed to allow comprehensive control over the fire-
wall’s behavior. You can define specific input and output rules, control the
order of logically similar sets of rules and make a distinction between rules
that apply to WAN and LAN devices.
To access the Advanced Filtering screen, select the
Advanced Filtering
tab. The
Advanced Filtering
screen will appear (see figure
5.17
).
Figure 5.17: Advanced Filtering
You can configure two sets of rules, Input rules and Output rules. Each set of
rules is comprised of three subsets: Initial rules, Network devices rules and
Final rules. These subsets determine the sequence by which the rules will be
applied. Following is a description of the set ordering for inbound and out-
bound packets.
Inbound packets – Input rule sets
• Initial rules.
• All rules defined for the network device on which the packet is.
• Local servers rules from the
Local servers
tab in the security screen.
• Rules to accept all the packets on a device in case the firewall check box
Internet connection firewall
in the connection settings screen is unchecked.
• Remote administration rules from the
Remote administration
tab.
• DMZ host rules from the
DMZ host
tab.
• Final rules.
Outbound packets – Output rules sets
122