Chapter 25 Firewall
UAG5100 User’s Guide
257
Figure 180
Blocking All LAN to WAN IRC Traffic Example
Your firewall would have the following rules.
• The first row blocks LAN access to the IRC service on the WAN.
• The second row is the firewall’s default policy that allows all LAN1 to WAN traffic.
The UAG applies the firewall rules in order. So for this example, when the UAG receives traffic from
the LAN, it checks it against the first rule. If the traffic matches (if it is IRC traffic) the firewall takes
the action in the rule (drop) and stops checking the firewall rules. Any traffic that does not match
the first firewall rule will match the second rule and the UAG forwards it.
Now suppose you need to let the CEO use IRC. You configure a LAN1 to WAN firewall rule that
allows IRC traffic from the IP address of the CEO’s computer. You can also configure a LAN to WAN
rule that allows IRC traffic from any computer through which the CEO logs into the UAG with his/her
user name. In order to make sure that the CEO’s computer always uses the same IP address, make
sure it either:
• Has a static IP address,
or
• You configure a static DHCP entry for it so the UAG always assigns it the same IP address (see
for information on DHCP).
Now you configure a LAN1 to WAN firewall rule that allows IRC traffic from the IP address of the
CEO’s computer (172.16.1.7 for example) to go to any destination address. You do not need to
specify a schedule since you want the firewall rule to always be in effect. The following figure shows
the results of your two custom rules.
Table 113
Blocking All LAN to WAN IRC Traffic Example
#
USER
SOURCE
DESTINATION
SCHEDULE
SERVICE
ACTION
1
Any
Any
Any
Any
IRC
Deny
2
Any
Any
Any
Any
Any
Allow
Содержание UAG5100
Страница 42: ...Chapter 3 Printer Deployment UAG5100 User s Guide 42 ...
Страница 124: ...Chapter 10 Interfaces UAG5100 User s Guide 124 Figure 82 Configuration Network Interface Ethernet Edit External Type ...
Страница 125: ...Chapter 10 Interfaces UAG5100 User s Guide 125 Figure 83 Configuration Network Interface Ethernet Edit Internal Type ...
Страница 135: ...Chapter 10 Interfaces UAG5100 User s Guide 135 Figure 88 Configuration Network Interface PPP Add ...
Страница 213: ...Chapter 20 UPnP UAG5100 User s Guide 213 Figure 139 Network Connections My Network Places Properties Example ...
Страница 227: ...Chapter 24 Web Authentication UAG5100 User s Guide 227 Figure 152 Configuration Web Authentication Web Portal ...
Страница 228: ...Chapter 24 Web Authentication UAG5100 User s Guide 228 Figure 153 Configuration Web Authentication User Agreement ...
Страница 273: ...Chapter 26 Billing UAG5100 User s Guide 273 Figure 190 Configuration Billing Payment Service Custom Service ...
Страница 292: ...Chapter 30 IPSec VPN UAG5100 User s Guide 292 Figure 201 Configuration VPN IPSec VPN VPN Connection Add Edit ...
Страница 298: ...Chapter 30 IPSec VPN UAG5100 User s Guide 298 Figure 203 Configuration VPN IPSec VPN VPN Gateway Add Edit ...
Страница 314: ...Chapter 30 IPSec VPN UAG5100 User s Guide 314 ...
Страница 387: ...Chapter 39 Certificates UAG5100 User s Guide 387 Figure 256 Configuration Object Certificate Trusted Certificates Edit ...
Страница 436: ...Chapter 42 Log and Report UAG5100 User s Guide 436 Figure 302 Configuration Log Report Email Daily Report ...
Страница 440: ...Chapter 42 Log and Report UAG5100 User s Guide 440 Figure 304 Configuration Log Report Log Settings Edit System Log ...
Страница 445: ...Chapter 42 Log and Report UAG5100 User s Guide 445 Figure 306 Configuration Log Report Log Settings Edit Remote Server ...
Страница 491: ...Appendix A Legal Information UAG5100 User s Guide 491 Environmental Product Declaration ...