Firewall configuration
Digi TransPort User Guide
655
Firewall scripts
A firewall is a protection system designed to prevent your local area network from unauthorized
external access by other users of the Internet or another wide area network. It can also limit the
degree of access local users have to external network resources. A firewall does not provide a
complete security solution; it provides only one element of a fully secure system. Consider using
additional security methods, such as user authentication and data encryption. Refer to the IPSec
section for further information.
A firewall is a packet filtering system that allows or prevents the transmission of data (in either
direction) based on a set of rules. These rules allow filtering based on the following criteria:
• Source and destination IP addresses
• Source and destination IP port or port ranges
• Type of protocol in use
• Direction of the data (in or out)
• Interface type
• The eroute the packet is on
• Whether an interface is OOS (out of service)
• ICMP message type
• TCP flags (
SYN
,
ACK
,
URG
,
RESET
,
PUSH
,
FIN
)
• TOS field
• Status of a link and/or data packets on UDP/TCP and ICMP protocols
Besides providing comprehensive filtering facilities, Digi TransPort routers support rules relating
to the logging of information for audit/debugging purposes. This information can be logged to a
pseudo-file on the router called
FWLOG.TXT
, the
EVENTLOG.TXT
pseudo-file or to a syslog server,
and can also be used to generate SNMP traps.
Firewall Script syntax
A firewall must be individually configured to match the needs of authorized users and their
applications. On Digi routers, the rules governing firewall behavior are defined in a script file
called
FW.TXT
. Each line in this file consists of a label definition, a comment or a filter rule.
Labels
A label definition is a string of up to 12 characters followed by a colon. Labels can only include
letters, digits and the underscore character. They used with the break option to cause the
processing of the script to jump to a new location.
Comments
Any line starting with the hash character (
#
) is considered a comment and is ignored.
Содержание TransPort
Страница 1: ...User Guide Digi TransPort ...
Страница 95: ...Regulatory and safety statements Digi TransPort User Guide 95 TransPort WR41Declaration of Conformity ...
Страница 96: ...Regulatory and safety statements Digi TransPort User Guide 96 ...
Страница 97: ...Regulatory and safety statements Digi TransPort User Guide 97 TransPort WR44 Declaration of Conformity ...
Страница 773: ...Manage files Digi TransPort User Guide 773 For example ...