162
McAfee UTM Firewall 4.0.4 Administration Guide
Firewall menu options
Packet filtering
Rules are evaluated from top to bottom as displayed on the page. The first matching rule determines the
action for the network traffic. To reorder a rule, click the move up or down arrow.
Note:
A “-” in the Hits or Hits Over Limit column indicates that no applicable interfaces are configured.
Creating a packet filter rule
Use this procedure to create a packet filter rule. When adding a rule, you can either use Predefined
addresses or services that have already been added under Definitions, or click New to manually enter an
address or service. For procedures on defining services and address and interface groups, refer to the
Definitions
. To return to the predefined definitions list for a field, click Show Definitions.
1
From the Firewall menu, click Packet Filtering. The Packet Filters Rules page appears.
2
If this is the first rule defined on the page, click New. Otherwise, click the add above or below icon at the
location where you want to add the rule. The Packet Filter Rule page appears (
Figure 167
).
Figure 167 Packet Filter Rule page
3
[Optional] Enter a descriptive name in the Descriptive Name field.
4
Make sure the Enable checkbox is selected. It is enabled by default. To temporarily disable the rule, clear
the checkbox.
5
From the Action list, select an option that specifies what to do if the rule matches. Available options are:
• None – [Default] Performs no action for this rule, which is useful for a rule that logs packets but
performs no other action.
• Accept – Allows the traffic.
• Drop – Disallows the traffic and silently discards the packets.The Drop action is useful for handling
packets from external untrusted hosts.
• Reject – Disallows the traffic, but also sends an ICMP port unreachable message to the source IP
address to advise that the packets were discarded. The Reject action is useful for packets from trusted
internal hosts if you have, for example, changed the default outbound policy from allow all packets out
to reject all, and then create packet filter rules for specific services and protocols that are allowed to
pass traffic out of the appliance.
6
The Type controls which incoming and outgoing interface options are available:
Содержание SG310
Страница 1: ...McAfee UTM Firewall Administration Guide version 4 0 4...
Страница 10: ...10 McAfee UTM Firewall 4 0 4 Administration Guide...
Страница 127: ...McAfee UTM Firewall 4 0 4 Administration Guide 127 Network Setup menu options DHCP Server Figure 130 DHCP Addresses page...
Страница 148: ...148 McAfee UTM Firewall 4 0 4 Administration Guide Network Setup menu options SIP...
Страница 238: ...238 McAfee UTM Firewall 4 0 4 Administration Guide Firewall menu options Antispam TrustedSource...
Страница 372: ...372 McAfee UTM Firewall 4 0 4 Administration Guide System menu features Advanced menu...
Страница 410: ...410 McAfee UTM Firewall 4 0 4 Administration Guide Index...
Страница 411: ......
Страница 412: ...700 2237A00...