Establishing security
172 Avaya VPNmanager Configuration Guide Release 3.7
22. For maximum flexibility and capability, the firewall rules can be specified on each interface:
Public, Private, or Tunnel. The packets are checked against the firewall rules at the
interface where they are defined.
23. Select the Direction from the drop-down list.
24. Direction is in respect to the security gateway: in or out.
25. If this rule is to be logged, select the Log Enable check box.
26. If this rule is to keep state, select the KeepState Enable check box.
27. The keepstate function allows a rule set for the intended traffic to also be applied to the
reply packets. The function can be applied to TCP, UDP, and ICMP packets.
28. Keepstate sets up a state table with each entry set up by the sending side. Reply packets
pass through a matching filter based on the respective state table en try. A state entry is not
created for packets that are denied.
29. Click Advanced to change the default keepstate values to TCP, UDP, or ICMP.
30. Click Finish to return to the Firewall Template General Tab.
Services
The Services property provides a list of predefined traffic types and user-defined traffic types
that facilitate the definition of the firewall and Quality of Service (QoS) rules. For instance, you
can add a user-defined service for use in firewall rules that allows or blocks a specific type of
traffic.
Figure 54: Services property
The VPNmanager provides predefined services. The supported predefined services are listed in
the Contents column of the Services object.