Firewall
Firewall Access Rule Configuration Examples
Cisco ISA500 Series Integrated Security Appliance Administrator Guide
187
6
-
Specific Times:
Choose this option if you want to keep
the access rule
active at specific times. Specify the
Start Time
and
End Time
by
entering the hour and minute.
STEP 4
Click
OK
to save your settings.
STEP 5
Click
Save
to apply your settings.
Firewall Access Rule Configuration Examples
This section provides some configuration examples on adding firewall access and
NAT rules.
Allowing Inbound traffic to an Internal FTP server using the WAN IP Address
User Case:
You host a FTP server on your LAN. You want to open the FTP server
to Internet by using the IP address of the WAN1 interface. The inbound traffic is
addressed to your WAN1 IP address but is directed to the FTP server.
Solution:
You can create a port forwarding rule or an Advanced NAT rule to open
the internal FTP server to Internet, and create a firewall access rule to allow the
access.
STEP 1
Set the IP address 172.39.202.101 to the WAN1 interface.
STEP 2
Create a host address object with the IP 192.168.1.100 called “InternalFTP”.
STEP 3
Go to the
Firewall -> NAT -> Port Forwarding
page to create a port forwarding
rule as follows.
Original Service
FTP-CONTROL
Translated Service
FTP-CONTROL
Translated IP
InternalFTP
WAN
WAN1
WAN IP
WAN1_IP
Enable Port Forwarding
On