
Firewalls and Tunnels
5-24
Hewlett-Packard Company Virtual Private Networking Concepts Guide
One-Way Out Firewall Rules
One-Way Out Firewall Rules
One-Way Out Firewall Rules
One-Way Out Firewall Rules
One-way out firewall rules allow devices on a red (trusted)
network to establish communication sessions with devices on a
black (untrusted) network. One-way out firewall rules allow
users on routed red (trusted) subnets to have access to services
on a black (untrusted) subnet.
No network address translation (NAT) is performed when a
session is established through a one-way out firewall rule.
Therefore, the source address of the packets leaving the red
(trusted) network must be routable on the black (untrusted)
network. Routable means that the devices on the black
(untrusted) network know how to send packets to the source
address.
If you want to allow people on the red (trusted) network to
browse the World Wide Web on the Internet, define a oneway out
firewall rule as described in the following table.
Parameter
Parameter
Parameter
Parameter
Description
Description
Description
Description
Parameter Value
Parameter Value
Parameter Value
Parameter Value
Comments
Comments
Comments
Comments
From IP address
198.53.144.0
This address allows
anyone on the red
(trusted) network
whose IP address
starts with
198.53.144.
From subnet mask
255.255.255.0
From application
port
ALL
The application port
used to make the
HTTP (www)
request is usually
unknown.
To IP address
0.0.0.0
This address allows
you to go to any
Web site on the
Internet.