Intel 9515, 9525, 9535 manual Action Discard Protocol

Page 24

DMZ Firewall Solution for the Express Router

Filter

9

10

11

12

13

14

Function

Discards all ICMP packets entering the DMZ network. This prevents the router from reporting the IP netmask. These filters must include all IP addresses on the router, including the WAN IP address if the router is using numbered links.

Two filters are required.

Discards all packets to open router ports.

Four filters are required.

Settings

Action:

Discard

Protocol:

ICMP

Dest. address type:

Host

Dest. address:

<LAN1 IP address>

Scr. address type:

All

 

 

Action:

Discard

Protocol:

ICMP

Dest. address type:

Host

Dest. address:

<LAN2 IP address>

Scr. address type:

All

Action:

Discard

Protocol:

UDP

dest address type:

Host

dest address:

<LAN1 IP address>

Dest. port:

All

Src. address type:

All

Src. port:

All

Action:

Discard

Protocol:

UDP

dest address type:

Host

dest address:

<LAN2 IP address>

Dest. port:

All

Src. address type:

All

Src. port:

All

Action:

Discard

Protocol:

TCP

Flags:

All

dest address type:

Host

dest address:

<LAN1 IP address>

Dest. port:

All

Src. address type:

All

Src. port:

All

Action:

Discard

Protocol:

TCP

flags:

All

dest address type:

Host

dest address:

<LAN2 IP address>

Dest. port:

All

Src. address type:

All

Src. port:

All

07-12-99

Version 1.0

23

Image 24
Contents DMZ Firewall Solution Copyright 1999, Intel Corporation. All rights reserved Table of Contents What is a DMZ IntroductionAbout This Document ReferencesGeneral Setup and Considerations IP Filters in the Express RouterIP Address Selection Routing Setup DNS SetupMail Smtp Setup FTP SetupDMZ Single IP Address Solution Static Routing SetupNetwork Address Translation NAT Setup IP Filters Setup SettingsEntry Function Receive Rx Filters on LAN1Filter Function Transmit Tx Filters on LAN1Src. address 10.2.0.2 Src. port Action Pass Protocol 2 LAN2 Filters Receive Rx Filters on LAN2Filter Function Settings RIPTransmit Tx filters on LAN2 Settings Internet Connection Filters Receive Rx Filters on the connection to the InternetAction Pass Protocol UDP Transmit Tx Filters on the Connection to the Internet DMZ Multiple IP Address Solution IP Address AssignmentNetwork Address Translation NAT Transmit Tx Filters on LAN1 Settings Src. port Action Pass Protocol Dest. address type All Dest port Src. address type All Src. port Action Discard Protocol Action Discard Protocol Transmit Tx filters on LAN2 Src. port 1023 Action Pass Protocol UDP Transmit Tx Filters on the Connection to the Internet