25
Chapter 6: Security Tab
EdgeRouter
™
Lite User Guide
Ubiquiti Networks, Inc.
Save Rule Order
To change the rule order, click and drag
a rule up or down the sequence, and then release the rule.
When you are finished, click
Save Rule Order
.
Search
Allows you to search for specific text. Begin
typing; there is no need to press
enter
. The results are
filtered in real time as soon as you type two or more
characters.
A table displays the following information about each rule.
Click a column heading to sort by that heading.
Order
The rules are applied in the order specified. The
number of the rule in this order is displayed.
Description
The keywords you entered to describe this
rule are displayed.
Source Addr.
The source IP address is displayed.
Source Port
The source port number is displayed.
Dest. Addr.
The destination IP address is displayed.
Dest. Port
The destination port number is displayed.
Translation
A description of the translation (such as
masquerade to eth_
) is displayed.
Count
The number of translations is displayed.
Actions
Click the
Actions
button to access the following
options:
•
Config
To configure the rule, click
Config
. Go to the
Add or Configure a Source NAT Rule
section below.
•
Copy
To create a duplicate, click
Copy
. The duplicate
rule appears at the bottom of the list.
•
Delete
Remove the rule.
Add or Configure a Source NAT Rule
After you click
Config
, the
Source NAT Rule Configuration
screen appears.
•
Description
Enter keywords to describe this rule.
•
Enable
Check the box to enable this rule.
•
Outbound Interface
Select the interface through
which the outgoing packets exit the EdgeRouter. This is
required only for Source NAT Rules that use Masquerade.
•
Translation
Select one of the following:
-
Use Masquerade
Masquerade is a type of Source
NAT. If enabled, the source IP address of the packets
becomes the public IP address of the outbound
interface.
-
Specify address and/or port
If enabled, the source
IP address of the packets becomes the specified IP
address and port.
•
Address
Enter the IP address that will replace the
source IP address of the outgoing packet. You can
also enter a range of IP addresses; one of them will
be used.
•
Port
Enter the port number that will replace the
source port number of the outgoing packet. You
can also enter a range of port numbers; one of them
will be used.
•
Exclude from NAT
Check the box to exclude packets
that match this rule from NAT.
•
Enable Logging
Check this box to log instances when
the rule is matched.
•
Protocol
Select one of the following:
-
All protocols
Match packets of all protocols.
-
Both TCP and UDP
Match TCP and UDP packets.
-
Choose a protocol by name
Select the protocol from
the drop-down list. Match packets of this protocol.
•
Match all protocols except for this
Match packets
of all protocols except for the selected protocol.
-
Enter a protocol number
Enter the port number of
the protocol. Match packets of this protocol.
•
Match all protocols except for this
Match packets
of all protocols except for the selected protocol.
Summary of Contents for ERLite-3
Page 1: ...3 Port Router...