Siemens 5890 manual Protocol/Port, Application

Page 83

SIEMENS 5890 DSL Router

Chapter 6 Security Setup

User’s Guide

Stateful Firewall

 

 

5.For Target, select one of the following to specify the characteristics a packet must have in order to match the firewall rule:

Protocol/Port

Specifies the protocol or port that applies to the rule. This can be one of the following:

-tcp to specify TCP protocol for this rule. You can specify a source and destination port or port range. If only one source/destination port is specified, the packet must have the specified port. If a range is defined, the packet can have a port within the specified range. If no source/destination port is specified, the firewall rule matches any port in the range 0 - 65535.

-udp to specify UDP protocol for this rule. You can specify a source and destination port or port range. If only one source/destination port is specified, the packet must have the specified port. If a range is defined, the packet can have a port within the specified range. If no source/destination port is specified, the firewall rule matches any port in the range 0 - 65535.

-number to specify a protocol number.

-icmp to specify ICMP protocol for this rule. If you select this protocol, my must specify an ICMP Type for matching the packet source and ICMP Code for matching the packet destination.

Application

Select the application that must match from the Application drop-down menu.

6.For Source and Destination under Address, optionally specify the First IP and Last IP addresses to define the source and destination IP address boundaries to apply to the firewall rule. The packet must have a source/destination IP address within the specified address range. If only First IP address is specified, the packet must have that source/destination IP address. If no source/destination IP address is specified, the firewall rule matches any valid IPV4 address.

7.For Source and Destination under Address, optionally specify a Mask that must match for the rule to apply. If no mask is specified, 255.255.255.255 is used.

8.From the Mode drop-down menu, select one of the following to specify when watch messages are displayed for this firewall rule. The messages are sent to the console serial port and a Syslog server.

Quiet: No messages are displayed for this firewall rule, even if the rule causes a packet to be dropped. This is the default setting for firewall allow rules.

Verbose: A message is displayed every time this firewall rule matches a packet, regardless of the rule action.

9.From the Direction drop-down menu, select the direction of the packet to which the firewall rule is applied. The default is both.

10.Click Save.

SIEMENS

77

Image 83
Contents 5890 Software License Software License and Limited WarrantyGeneral Provisions Table of Contents Security Setup User SetupAdvanced Setup Monitoring Router Back Panel Front PanelHardware Specifications Software Specifications Security Frame RelayPPP RFC 1661, RFC PC Requirements Installation RequirementsPackage Contents Network Service Provider Requirements Hardware Installation Windows 98/ME PC ConfigurationSelect TCP/IP Protocol from the Network Protocols list Windows NTWindows Windows XP Mac OS Mac OSX Linux Establish Connection Configuring the RouterTo do this Refer to Router InformationSelect Protocol Access Easy Setup WizardPoint-to-Point Protocol over ATM VC Multiplexing Bridging EnabledIP Routing Enabled Block Net Bios Traffic NAT EnabledPoint-to-Point Protocol over ATM LLC Encapsulation NAT Enabled RFC 1483 Multiprotocol Encapsulation LLC/SNAP RFC 1483 VC Multiplexing Routed Point-to-Point Protocol over Ethernet over RFC1483 RFC 1483 MAC Encapsulated Routing MER RAW IP Dynamic Host Configuration Protocol Local Area Network Configuration User Management User SetupAdding/Modifying a User Account Deleting a User Account None User LookupLocal RadiusUntrusted Secure Mode ConfigurationTrusted Configure the Radius Server Configure the TacPlus Server Class Functional Areas Management ClassesChange Password Telnet Web Access ControlNo access restrictions Click Save and RebootAdvanced Setup Sdsl ATM or Sdsl Frame Relay WAN SelectionRemote File Configuration DMZ DMZ Router Clock Dhcp Dhcp QoS Differentiated Services FrameworkWeighted Fair Queuing Configure QoS policies Configure QoS Policy Siemens Before policy Reorder QoS PoliciesTo the end Routing Table Configuration Click Enable Dial Backup Dial BackupATM Traffic Shaping Unspecified Bit Rate Constant Bit RateReal-Time Variable Bit Rate Non Real-Time Variable Bit RateSwitch Management Switch Mirror Configuration Switch Age Time Command Line Interface File Editor Security Setup NAT NAT Server Configuration NAT Host Mapping Port Number DisableDefault Click Add IP Range Snmp IP FilterEnter the New Password and New Password again Snmp PasswordKey Generator Secure ShellConfigure SSH Load Keys Key Generator Firewall Scripts Firewall Rules Stateful FirewallConfigure Stateful Firewall View Dropped Packets Configure Firewall Rules Application Protocol/PortDelete Firewall Rules IKE/IPSec Configuration Easy IKE/IPSec Setup IKE Peers Advanced IKE/IPSec SetupIKE Peers Definition IKE Proposals Definition IKE IPSec Proposals Definition Siemens IKE IPSec Policies Definition Siemens VPN Log On System Summary Monitoring RouterRemote Connection Information Ethernet Interface InformationSystem Information IP Routing InformationPPPoE Session DiagnosticsATM Statistics Interface InformationFiles Information Routing Table InformationMemory Usage List All Configuration DataTCP/IP Statistics