Intel 9525, 9515, 9535 manual Src. address 10.2.0.2 Src. port Action Pass Protocol

Page 10

DMZ Firewall Solution for the Express Router

Filter Function

2Allows FTP (only passive connections) from secure LAN to the FTP proxy server on the DMZ (see note 1).

Two filters are required.

3

4Allows incoming mail (SMTP) from DMZ to secure LAN.

5Allows outgoing mail (SMTP) from secure LAN to DMZ.

6Allows incoming News (NNTP) from DMZ to secure LAN (see note 2).

7Allows outgoing News (NTTP) to DMZ from secure LAN.

Settings

Src. address:

10.2.0.2

Src. port:

= 80

Action:

Pass

Protocol:

TCP

TCP flags:

ACK

Dest. address type:

All

Dest. port:

>1023

Src. address type:

Host

Src. address:

10.2.0.2

Src. port:

= 21

Action:

Pass

Protocol:

TCP

TCP flags:

ACK

Dest. address type:

All

Dest. port:

>1023

Src. address type:

Host

Src. address:

10.2.0.2

Src. port:

>1023

Action:

Pass

Protocol:

TCP

TCP flags:

All

Dest. address type:

Host

Dest. address:

10.5.0.1

Dest. port:

= 25

Src. address type:

Host

Src. address:

10.2.0.3

Src. port:

> 1023

Action:

Pass

Protocol:

TCP

TCP flags:

ACK

Dest. address type:

Host

Dest. address:

10.5.0.1

Dest. port:

> 1023

Src. address type:

Host

Src. address:

10.2.0.3

Src. port:

= 25

Action:

Pass

Protocol:

TCP

TCP flags:

All

Dest. address type:

Host

Dest. address:

10.5.0.2

Dest. port:

= 119

Src. address type:

Host

Src. address:

10.2.0.4

Src. port:

> 1023

Action:

Pass

Protocol:

TCP

TCP flags:

ACK

Dest. address type:

Host

07-12-99

Version 1.0

9

Image 10
Contents DMZ Firewall Solution Copyright 1999, Intel Corporation. All rights reserved Table of Contents About This Document What is a DMZIntroduction ReferencesIP Filters in the Express Router General Setup and ConsiderationsIP Address Selection Mail Smtp Setup Routing SetupDNS Setup FTP SetupStatic Routing Setup DMZ Single IP Address SolutionNetwork Address Translation NAT Setup Entry Function IP Filters SetupSettings Receive Rx Filters on LAN1Filter Function Transmit Tx Filters on LAN1Src. address 10.2.0.2 Src. port Action Pass Protocol 2 LAN2 Filters Receive Rx Filters on LAN2Filter Function Settings RIPTransmit Tx filters on LAN2 Settings Internet Connection Filters Receive Rx Filters on the connection to the InternetAction Pass Protocol UDP Transmit Tx Filters on the Connection to the Internet DMZ Multiple IP Address Solution IP Address AssignmentNetwork Address Translation NAT Transmit Tx Filters on LAN1 Settings Src. port Action Pass Protocol Dest. address type All Dest port Src. address type All Src. port Action Discard Protocol Action Discard Protocol Transmit Tx filters on LAN2 Src. port 1023 Action Pass Protocol UDP Transmit Tx Filters on the Connection to the Internet