Intel 9515, 9525, 9535 manual Action Pass Protocol

Page 15

DMZ Firewall Solution for the Express Router

Filter

2

3

4

5

6

7

8

Function

Allows FTP (both active and passive) from the Internet to the HTTP/FTP server on the DMZ.

Three filters are required.

Allows external ping to HTTP/FTP server on the DMZ.

Allows external HTTP from HTTP/FTP proxy on the DMZ.

Allows external FTP from the HTTP/FTP proxy server on the DMZ (see note 1).

Two filters are required.

Settings

Action:

Pass

Protocol:

TCP

TCP flags:

All

Dest. address type:

Host

Dest. address:

10.2.0.1

Dest. port:

= 21

Src. address type:

All

Src. port:

> 1023

Action:

Pass

Protocol:

TCP

TCP flags:

ACK

Dest. address type:

Host

Dest. address:

10.2.0.1

Dest. port:

= 20

Src. address type:

All

Src. port:

> 1023

Action:

Pass

Protocol:

TCP

TCP flags:

All

Dest. address type:

Host

Dest. address:

10.2.0.1

Dest. port:

>1023

Src. address type:

All

Src. port:

>1023

Action:

Pass

Protocol:

ICMP

Dest. address type:

Host

Dest. address:

10.2.0.1

Src. address type:

All

Action:

Pass

Protocol:

TCP

TCP flags:

ACK

Dest. address type:

Host

Dest. address:

10.2.0.2

Dest. port

> 1023

Src. address type:

All

Src. port:

= 80

Action:

Pass

Protocol:

TCP

TCP flags:

ACK

Dest. address type:

Host

Dest. address:

10.2.0.2

Dest. port

> 1023

Src. address type:

All

Src. port:

= 21

Action:

Pass

Protocol:

TCP

TCP flags:

ACK

Dest. address type:

Host

07-12-99

Version 1.0

14

Image 15
Contents DMZ Firewall Solution Copyright 1999, Intel Corporation. All rights reserved Table of Contents References What is a DMZIntroduction About This DocumentGeneral Setup and Considerations IP Filters in the Express RouterIP Address Selection FTP Setup Routing SetupDNS Setup Mail Smtp SetupDMZ Single IP Address Solution Static Routing SetupNetwork Address Translation NAT Setup Receive Rx Filters on LAN1 IP Filters SetupSettings Entry FunctionTransmit Tx Filters on LAN1 Filter FunctionSrc. address 10.2.0.2 Src. port Action Pass Protocol Receive Rx Filters on LAN2 2 LAN2 FiltersRIP Filter Function SettingsTransmit Tx filters on LAN2 Settings Receive Rx Filters on the connection to the Internet Internet Connection FiltersAction Pass Protocol UDP Transmit Tx Filters on the Connection to the Internet IP Address Assignment DMZ Multiple IP Address SolutionNetwork Address Translation NAT Transmit Tx Filters on LAN1 Settings Src. port Action Pass Protocol Dest. address type All Dest port Src. address type All Src. port Action Discard Protocol Action Discard Protocol Transmit Tx filters on LAN2 Src. port 1023 Action Pass Protocol UDP Transmit Tx Filters on the Connection to the Internet