ProSafe Wireless-N VPN Firewall SRXN3205 Reference Manual
5-6
Firewall Security and Content Filtering
v1.0, July 2008
Remember that allowing inbound services opens holes in your firewall. Only enable those ports
that are necessary for your network. It is also advisable to turn on the server application security
and invoke the user password or privilege levels, if provided.
Viewing the Firewall Rules
To view the firewall rules:
1.
Select
Security > Firewall
from the main/sub-menu. The LAN WAN Rules tab appears:
WAN Users
These settings determine which Internet locations are covered by the rule, based on
their IP addresses. Select the desired option:
• Any – All Internet IP address are covered by this rule.
• Single address – Enter the required address in the start field.
• Address range – If this option is selected, you must enter the start and end fields.
WAN Destination IP
Address
This setting determines the destination IP address applicable to incoming traffic.
This is the public IP address that will map to the internal LAN server; it can either be
the address of the WAN1 or WAN2 ports or another public IP address
.
Log
This determines whether packets covered by this rule are logged. Select the desired
action:
• Always – Always log traffic considered by this rule, whether it matches or not. This
is useful when debugging your rules.
• Never – Never log traffic considered by this rule, whether it matches or not.
Note:
Some residential broadband ISP accounts do not allow you to run any server
processes (such as a Web or FTP server) from your location. Your ISP may
periodically check for servers and may suspend your account if it discovers any
active services at your location. If you are unsure, refer to the Acceptable Use
Policy of your ISP.
Table 5-2. Inbound Rules (continued)
Item
Description