312
You should enable logging only for diagnostic purposes or
for rules which are not used frequently. Otherwise your log
files may grow rapidly.
Protocol
Select one of the protocols from the list. Each protocol represents a set of IP
protocol and port definitions. You will find the details in menu "Definitions >
Protocols". This is also where you can extend the list with your own protocol
definitions.
Source zone
Use this setting to restrict the rule to connections originating in a specific zone.
Source IP/network
If you leave these fields blank, the rule will apply to any source IP. To grant
access for a single client only, please enter its IP address. To give access for a
whole network, specify the network address and its corresponding netmask (e.g.
192.168.0.0/24). To configure a rule for multiple individual clients or networks,
define a new group in menu "Definitions > IP objects" or select an entry from the
list of available groups.
Policy
Access may either be allowed or forbidden. When denying a connection, SX-
GATE can either silently discard the IP packet or reject it with an "administratively
prohibited" ICMP reply message. The latter indicates the reason for the
connection failure to the sender.
Dest. (
…
)
If you leave these fields blank, the rule will apply to any destination IP. To grant
access to a single server only, please enter its IP address. To give access to a
whole network, specify the network address and its corresponding netmask (e.g.
192.168.0.0/24). To configure a rule for multiple individual clients or networks,
define a new group in menu "Definitions > IP objects" or select an entry from the
list of available groups.
Period
You may want to enable certain rules only on specific weekdays during a certain
period of time. Here you can assigne one of the periods defined in menu
"Definitions > Periods".
DoS
If you like you can also activate the Denial-of-Service protection by the dynamic
firewall. For TCP the value refers to the maximum number of connections per
source IP. For all other protocols you specify the number of packets per source IP.
Comment
Use this field for documentation. Up to 14 characters from this field will be included
in the log if logging is enabled for this rule.