QuadroCS Manual II: Administrator's Guide
Administrator's Menus
Quadro
CS
(SW Version 3.0.x)
40
Firewall
The
Firewall Configuration
page allows setting up a firewall, configuring the security level of QuadroCS.
A
Firewall
is a security service configured by the QuadroCS administrator based on various criteria. The firewall allows or blocks traffic based on
policies, services and/or IP addresses. The firewall has several levels of security policies (low, medium, high). The administrator may add additional
service-based rules. Filtering rules will take effect only if the Firewall has been enabled and are independent from the selected firewall security level.
The
Firewall Configuration
page consists of the following
components:
The
Enable Firewall
checkbox selection enables the firewall
security service. The firewall security level has to be selected,
otherwise the firewall cannot be enabled.
The
Firewall Security
radio buttons are:
•
Low Security
- Everything that is not explicitly forbidden is
allowed. This security level doesn't block anything by
default. It is recommended if the device is already located
behind another firewall or if every filter has been configured
correctly.
•
Medium Security
- Traffic originating from the LAN side
may pass and traffic from the WAN side will be blocked by
default. This is the recommended security level.
•
High Security
- Everything that is not explicitly allowed will
be blocked,
including traffic from the LAN side.
Advanced Firewall Settings
link refers to page where QuadroCS
privacy can be configured.
The
View Filter Rules
link opens the
Filtering Rules
page.
Fig. II-59: Firewall and NAT Settings page
Advanced Firewall Settings
Advanced Firewall Settings
are used to deny Ping and
Portscanning operations addressed toward the device. With
these features enabled QuadroCS will answer with irritating
message to the Ping and Portscanning operations. Page
consists of the following components:
The
Ping Stealth
checkbox selection prohibits Ping operation
toward QuadroCS from its WAN.
The
Fool Portscanner
checkbox selection prohibits
QuadroCS portscanning from its WAN. As a reply to
Portscanning operation, "network unreachable" or "host
unreachable" feedback messages will be sent.
Fig. II-60: Advanced Firewall Settings page