86
9 Internet security
DMS3-CTC-25-282 v1.0
9.2 Firewall
Introduction
The TG789vac v2 comes with an integrated firewall that helps you protect your network from attacks from the Internet. This
firewall has a number of predefined levels to allow you to adjusted the firewall to your needs.
Predefined security levels
The TG789vac v2 has a number of predefined security levels. The following levels are available:
•
BlockAll
:
All traffic from and to the Internet is blocked. Game and Application Sharing is not allowed by the firewall.
•
Standard
:
All outgoing connections are allowed. All incoming connections are blocked, except for inbound connections assigned to
a local host via Game and Application Sharing. This is the
default firewall level
.
•
Disabled
:
All in- and outgoing traffic is allowed to pass through your TG789vac v2, including Game and Application Sharing.
Changing the security level
Proceed as follows:
1
Browse to the
.
For more information, see
“Accessing the TG789vac v2 GUI” on page 29
2
On the
Toolbox
menu, click
Firewall
.
3
The
Firewall
page appears. In the upper-right corner, click
Configure
.
4
Under
Security Settings
, select the security level of your choice and click
Apply
.
Creating your own security level
Proceed as follows:
1
In the
Toolbox
menu click
Firewall
.
2
In the
Firewall
section, go to the
Configure
page.
3
In the
Pick a task
list, click
Create a new Security Level
.
4
In the
Name
box, type a name for the new security level and select an existing security level to clone from.
5
Click
Apply
.
6
A page with the firewall settings of your newly created security level appears. Click
Edit
.
7
Enter the following information:
The
Name
of the firewall rule.
The
Source Interface
and
IP Address
(range).
Or you can type a
User-defined
IP address (range).
Although BlockAll will block all connections, some mandatory types of traffic such as DNS will still be relayed
between LAN and WAN by the TG789vac v2.
The firewall levels only have impact on traffic passing through your TG789vac v2. This means that the handling of
traffic directly appointed from and to TG789vac v2 is independent of the selected firewall level.
Protocol checks will be performed on all accepted connections, irrespective of the chosen level.
Once you create a security level, you can not delete it anymore. It will always available in the list of available security
levels.
Use
Any
as IP address in case all traffic for the interface should be parsed.