« 40 »
To edit a static IP address, click the edit button
next to the address in the Static Lists screen.
5.3.7 Basic Firewall
The ISA-4000 provides basic firewall functions, by filtering all the packets that enter the ISA-4000
using a set of rules. The rules are in an order sequence list—the lower the rule number, the higher
the priority the rule has. Each rule has four characteristics:
Priority
This is an order sequence list; the lower number the rule, the higher the priority.
Interface
This specifies which interface the rule applies to.
Protocol
This specifies which protocol the rule applies to.
Policy
This determines what will happen to any packets that match this firewall rule. The
ISA-4000 supports five policies: ACCEPT, DENY, REJECT, MASQ, and REDIRECT.
The definitions of the five policies are as follows:
•
ACCEPT:
if the packet matches the rule, the ISA-4000 will accept it.
•
DENY:
if the packet matches the rule, the ISA-4000 will discard it.
•
REJECT:
if the packet matches the rule, the ISA-4000 will discard it and notify
the sender that the packet was discarded.
•
MASQ:
if the packet matches the rule, the packet will be masqueraded, or
rewritten to appear as if it originated from the ISA-4000. When this policy is
selected, the ISA-4000 will provide NAT (Network Address Translation) service.
This policy is for forward rules only.
•
REDIRECT:
If the packet matches the rule, it will be redirected to one of the ISA-
4000's local ports. This port number is specified in the Redirect to Port Number
field. This feature is used for the applications such as proxy server, etc. This
policy is for input rules only.
In the firewall, a collection of rules is called a "chain.” Three chains are provided:
•
InputChain:
Incoming packets (those originating from an outside network and addressed to
the internal network) are filtered by the ISA-4000 according to the InputChain rules.
•
ForwardChain:
When an incoming packet from an external network requests forwarding to
another computer, it is filtered by the ISA-4000 according to the ForwardChain rules.
•
OutputChain:
Outgoing packets (those originating from the internal network, addressed to
the outside network) are filtered by the ISA-4000 according to the OutputChain rules.
5 . 3 . 7 . 1 E
N A B L I N G T H E F I R E W A L L
1. Click
Network Services
.
2. Click
Basic Firewall
. The Basic Firewall screens appears:
Figure 5-23: Basic firewall configuration
3. Check
Enable Firewall
.
4. Click
Save
. Click
Apply Changes Now
to activate the changes.