Intel 9535, 9515, 9525 manual Src. address type All Src. port Action Discard Protocol

Page 23

DMZ Firewall Solution for the Express Router

Filter Function

2Prevents tunnel packets from entering the DMZ network

3Prevents RSVP packets from entering the DMZ network/router. Three separate filters are required.

4

5

6Prevents BootP updates from entering the DMZ network/router.

7Prevents Syslog updates from entering the DMZ network/router

8Discards all packets that fake the IP address of the router on LAN1 as these packets are allowed to pass the Tx filter on LAN1

Settings

Src. address type:

All

Src. port:

All

Action:

Discard

Protocol:

TCP

Dest. address type:

All

Dest port:

Tunnel

Src. address type:

All

Src. port:

All

Action:

Discard

Protocol:

RSVP

Dest. address type:

All

Dest. port :

All

Src. address type:

All

Src. port :

All

Action:

Discard

Protocol:

UDP

Dest. address type:

All

Dest. port :

1698

Src. address type:

All

Src. port :

All

Action:

Discard

Protocol:

UDP

Dest. address type:

All

Dest. port :

1699

Src. address type:

All

Src. port :

All

Action:

Discard

Protocol:

UDP

Dest. address type:

All

Dest. port:

67

Src. address type:

All

Src. port:

All

Action:

Discard

Protocol:

UDP

Dest. address type:

All

Dest. port:

514

Scr. address type:

All

Src. port :

All

Action:

Discard

Protocol:

UDP

Dest. address type:

All

Dest. port:

All

Scr. address type:

Host

Src. address:

<LAN1 IP address>

Src. port :

All

07-12-99

Version 1.0

22

Image 23
Contents DMZ Firewall Solution Copyright 1999, Intel Corporation. All rights reserved Table of Contents References What is a DMZIntroduction About This DocumentIP Address Selection General Setup and ConsiderationsIP Filters in the Express Router FTP Setup Routing SetupDNS Setup Mail Smtp SetupNetwork Address Translation NAT Setup DMZ Single IP Address SolutionStatic Routing Setup Receive Rx Filters on LAN1 IP Filters SetupSettings Entry FunctionTransmit Tx Filters on LAN1 Filter FunctionSrc. address 10.2.0.2 Src. port Action Pass Protocol Receive Rx Filters on LAN2 2 LAN2 FiltersRIP Filter Function SettingsTransmit Tx filters on LAN2 Settings Receive Rx Filters on the connection to the Internet Internet Connection FiltersAction Pass Protocol UDP Transmit Tx Filters on the Connection to the Internet IP Address Assignment DMZ Multiple IP Address SolutionNetwork Address Translation NAT Transmit Tx Filters on LAN1 Settings Src. port Action Pass Protocol Dest. address type All Dest port Src. address type All Src. port Action Discard Protocol Action Discard Protocol Transmit Tx filters on LAN2 Src. port 1023 Action Pass Protocol UDP Transmit Tx Filters on the Connection to the Internet