« 41 »
5 . 3 . 7 . 2 A
D D I N G R U L E S T O I N P U T
/
F O R W A R D
/
O U T P U T C H A I N S
1. Click
Network Services
.
2. Click
Basic Firewall
.
3. Click
the
Input Chain
,
Forward Chain
, or
Output Chain button
.
4. In the Input/Forward/Output Chain screen, click
Add
. The Input/Forward/Output Chain
screen appears:
Figure 5-24: Input, forward, and output chain settings
For IP addresses and port numbers, leave the appropriate field empty to match any value.
The field definitions are as follows:
Source
Address
Source IP Address (Beginning of Range)
– This beginning (or
lowest) source IP address should be applied to the input chain.
Source IP Address (End of Range)
– This ending (or highest) source
IP address should be applied to the input chain.
Source Port Number(s)
– This source port number, or range thereof,
should be applied to the input chain. If you want to specify a range of
ports, use a colon (:) as a separator. For example, 10:20 corresponds
to the range from port 10 to port 20.
Destination
Address
Destination IP Address (Beginning of Range)
– This beginning (or
lowest) destination IP address should be applied to the input chain.
Destination IP Address (End of Range)
– This ending (or highest)
destination IP address should be applied to the input chain.
Destination Port Number(s)
– This destination port number, or range
thereof, should be applied to the input chain. If you want to specify a
range of ports, use colon (:) as a separator. For example, 10:20
corresponds to the range from port 10 to port 20.
Protocol &
Interface
Network Protocol
– this network protocol of the packets should be
applied to the input chain.
Network Interface
– this network interface of the packets should be
applied to the input chain.
Policy
Policy
– this is what happens to any packets that match this firewall
rule. The four policies to choose from are ACCEPT, DENY, REJECT,
and REDIRECT.
Redirect to Local Port Number
– If the REDIRECT policy is selected
above, packets that match this firewall rule will be directed to this port
number on the ISA-4000. For other policies, this field is ignored.
Note:
The Forward and Output Chain screens to not have the Redirect
to Local Port Number option.
5. Click
Save
.