Chapter6 Firewall Policy
Edit Firewall Policy/ACL
6-2
Cisco Router and Security Device Manager Version 2.2 Users Guide
OL-4015-08
3. Come to the Firewall Policy win dow to edit the firewall policy you
created. After configuring LAN and WAN interfaces and creating a firewall,
you can open this window and get a graphical representation of the policy in
a traffic flow. You can view the access rule and inspection rule entries and
make any necessary changes.
Use the Firewall Policy View Feature
After you have created the firewall, you can use the Firewall Policy View window
to get a graphical view of the firewall in the context of the router interfaces, and
to modify it if you need to.
The four major sections in this topic are:
Select a Traffic Flow
Examine the Traffic Diagram and Select a Traffic Direction
Make Changes to Access Rules and Inspection Rules as Necessary
Swap From and To Interfaces to Bring Other Rules into View
For a use case example, see Firewall Policy Use Case Scenario.
Note If the router is using a Cisco IOS image that does not supp ort the Firewall feature
set, only the Services area will be displayed, and you will only be able to create
access control entries.
Select a Traffic Flow
Use the From and To lists of interfaces to select a particular traffic flow: traffic
that enters the router on a specified From interface and that exits the router on a
specified To interface. SDM displays all interfaces that have IP addresses in
alphabetical order in both the From and To interface lists. By default, SDM selects
the first interface in the From list, and the second interface in the To list.
There must be a least two configured interfaces on the router. If there is only one,
SDM will display a message telling you to configure an additional interface. The
following graphic shows the Traffic Selection panel.