ProSafe Wireless-N VPN Firewall SRXN3205 Reference Manual
Firewall Security and Content Filtering
5-5
v1.0, July 2008
•
If your external IP address is assigned dynamically by your ISP (DHCP enabled), the IP
address may change periodically as the DHCP lease expires. Consider using
Dyamic DNS
(under Network Configuration) so that external users can always find your network (see
“Configuring Dynamic DNS (Optional)” on page 2-11
.
•
If the IP address of the local server PC is assigned by DHCP, it may change when the PC is
rebooted. To avoid this, use the Reserved IP address feature in the
LAN Groups
menu (under
Network Configuration) to keep the PC’s IP address constant (see
“Configuring DHCP
Address Reservation” on page 3-9
.
•
Local PCs must access the local server using the server’s local LAN address. Attempts by
local PCs to access the server using the external WAN IP address will fail.
Note:
See
“Enabling Port Triggering” on page 5-28
for yet another way to allow
certain types of inbound traffic that would otherwise be blocked by the
firewall.
Table 5-2. Inbound Rules
Item
Description
Service
Select the desired Service or application to be covered by this rule. If the desired
service or application does not appear in the list, you must define it using the
Services menu (see
“Adding Customized Services” on page 5-17
).
Action (Filter)
Select the desired action for packets covered by this rule:
• BLOCK always
• BLOCK by schedule, otherwise Allow
• ALLOW always
• ALLOW by schedule, otherwise Block
Note
: Any inbound traffic which is not allowed by rules you create will be blocked by
the Default rule.
Schedule
Select the desired time schedule (Schedule1, Schedule2, or Schedule3) that will be
used by this rule (see
“Setting Schedules to Block or Allow Traffic” on page 5-20
).
• This drop down menu gets activated only when “BLOCK by schedule, otherwise
Allow” or “ALLOW by schedule, otherwise Block” is selected as Action.
• Use schedule page to configure the time schedules.
Send to LAN Server This LAN address determines which computer on your network is hosting this service
rule. (You can also translate this address to a port number.)
Translate to Port
Number
Check the “Translate to Port Number” and enter a port number if you want to assign
the LAN Server to a different service port number. Inbound traffic to the service port
will have the destination port number modified to the port number configured here.