SIEMENS se5880 Ethernet Security Router
User’s Guide
Chapter 6 Security Setup
Stateful Firewall
SIEMENS
61
5. For
Target
, select one of the following to specify the characteristics a packet must have in order to match
the firewall rule:
•
Protocol/Port
Specifies the protocol or port that applies to the rule. This can be one of the following:
-
tcp
to specify TCP protocol for this rule. You can specify a source and destination port or port range.
If only one source/destination port is specified, the packet must have the specified port. If a range is
defined, the packet can have a port within the specified range. If no source/destination port is
specified, the firewall rule matches any port in the range 0 - 65535.
-
udp
to specify UDP protocol for this rule. You can specify a source and destination port or port range.
If only one source/destination port is specified, the packet must have the specified port. If a range is
defined, the packet can have a port within the specified range. If no source/destination port is
specified, the firewall rule matches any port in the range 0 - 65535.
-
number
to specify a protocol number.
-
icmp
to specify ICMP protocol for this rule. If you select this protocol, my must specify an ICMP Type
for matching the packet source and ICMP Code for matching the packet destination.
•
Application
Select the application that must match from the
Application
drop-down menu.
6. For
Source
and
Destination
under
Address
, optionally specify
the
First IP
and
Last IP
addresses to
define the source and destination IP address boundaries to apply to the firewall rule. The packet must
have a source/destination IP address within the specified address range. If only
First IP
address is
specified, the packet must have that source/destination IP address. If no source/destination IP address is
specified, the firewall rule matches any valid IPV4 address.
7. For
Source
and
Destination
under
Address
, optionally specify a
Mask
that must match for the rule to
apply. If no mask is specified, 255.255.255.255 is used.
8. From the
Mode
drop-down menu, select one of the following to specify when watch messages are
displayed for this firewall rule. The messages are sent to the console serial port and a Syslog server.
•
Quiet
: No messages are displayed for this firewall rule, even if the rule causes a packet to be dropped.
This is the default setting for firewall
allow
rules.
•
Verbose
: A message is displayed every time this firewall rule matches a packet, regardless of the rule
action.
9. From the
Direction
drop-down menu, select the direction of the packet to which the firewall rule is applied.
The default is
both
.
10. Click
Save
.