Intel 9515, 9525, 9535 manual Filter Function Settings, Rip

Page 12

DMZ Firewall Solution for the Express Router

Filters are defined as follows:

Filter

Function

Settings

Pass all packets destined for DMZ

Default Action:

Pass

1

Prevents RIP updates from entering the

Action:

Discard

 

DMZ network

Protocol:

UDP

 

 

Dest. address type:

All

 

 

Dest. port:

RIP

 

 

Src. address type:

All

 

 

Src. port:

All

2

Prevents tunnel packets from entering

Action:

Discard

 

the DMZ network

Protocol:

TCP

 

 

Dest. address type:

All

 

 

Dest. port:

Tunnel

 

 

Src. address type:

All

 

 

Src. port:

All

3

Prevents RSVP packets from entering

Action:

Discard

 

the DMZ network/router.

Protocol:

RSVP

 

 

Dest. address type:

All

 

Three separate filters are required.

Dest. port :

All

 

 

Src. address type:

All

 

 

Src. port :

All

4

 

Action:

Discard

 

 

Protocol:

UDP

 

 

Dest. address type:

All

 

 

Dest. port :

= 1698

 

 

Src. address type:

All

 

 

Src. port :

All

5

 

Action:

Discard

 

 

Protocol:

UDP

 

 

Dest. address type:

All

 

 

Dest. port :

= 1699

 

 

Src. address type:

All

 

 

Src. port :

All

6

Prevents BootP updates from entering

Action:

Discard

 

the DMZ network/router.

Protocol:

UDP

 

 

Dest. address type:

All

 

 

Dest. port:

67

 

 

Src. address type:

All

 

 

Src. port:

All

7

Prevents Syslog updates from entering

Action:

Discard

 

the DMZ network/router

Protocol:

UDP

 

 

Dest. address type:

All

 

 

Dest. port:

= 514

 

 

Scr. address type:

All

 

 

Src. port :

All

8

Discards all packets that spoof (or fake)

Action:

Discard

 

the IP address of the router on LAN1.

Protocol:

UDP

 

This is necessary since these packets

Dest. address type:

All

 

will pass the Tx filter on LAN1.

Dest. port:

All

07-12-99

Version 1.0

11

Image 12
Contents DMZ Firewall Solution Copyright 1999, Intel Corporation. All rights reserved Table of Contents What is a DMZ IntroductionAbout This Document ReferencesGeneral Setup and Considerations IP Filters in the Express RouterIP Address Selection Routing Setup DNS SetupMail Smtp Setup FTP SetupDMZ Single IP Address Solution Static Routing SetupNetwork Address Translation NAT Setup IP Filters Setup SettingsEntry Function Receive Rx Filters on LAN1Filter Function Transmit Tx Filters on LAN1Src. address 10.2.0.2 Src. port Action Pass Protocol 2 LAN2 Filters Receive Rx Filters on LAN2Filter Function Settings RIPTransmit Tx filters on LAN2 Settings Internet Connection Filters Receive Rx Filters on the connection to the InternetAction Pass Protocol UDP Transmit Tx Filters on the Connection to the Internet DMZ Multiple IP Address Solution IP Address AssignmentNetwork Address Translation NAT Transmit Tx Filters on LAN1 Settings Src. port Action Pass Protocol Dest. address type All Dest port Src. address type All Src. port Action Discard Protocol Action Discard Protocol Transmit Tx filters on LAN2 Src. port 1023 Action Pass Protocol UDP Transmit Tx Filters on the Connection to the Internet