6-7
Cisco Router and Security Device Manager Version 2.2 Users Guide
OL-4015-08
Chapter6 Firew all Policy
Edit Firewall Policy/ACL
the Extended entry dialog when you add an entry from t he Edit Firewall
Policy/ACL window. If you want to add a standard rule entry, you can do so in the
Rules window.
EditClick to edit a selected access rule entry. Although you can only add
extended rule entries in the Edit Firewall Policy/ACL window, you are not
prevented from editing a standard rule entry that has already been a pplied to a
selected interface.
CutClick to remove a selected access rule entry. The entry is placed on the
clipboard and can be pasted to another position in the list, or it can be pasted to
another access rule. If you want to reorder an entry, you can cut the entry from
one location, select an entry before or after the location that you want for the cut
entry, and click Paste. The Paste context menu allows you to place the entry
before or after the entry you selected.
CopySelect a rule entry and click to put the rule entry on the clipboard.
PasteClick to paste an entry on the clipboard to the selected rule. You will be
prompted to specify whether you want to paste the entry before or after the
currently selected entry. If SDM determines that an identical entry already exists
in the access rule, it displays the Add an Extended Rule Entry window so that you
can modify the entry. SDM does not allow duplicate entries in the same access
rule.
If there is an existing standard rule that filters the returning traffic flow to which
you are applying the firewall, SDM informs you that it will convert the standard
access rule to an extended rule.
ExamplesTo apply a firewall that protects the network connected to the
Ethernet 0 interface from traffic entering the Ethernet 1 interface, select From:
Ethernet 0, and To: Ethernet 1. Then click Apply Firewall.
If the selected traffic flow does not have a firewall applied,
you can apply a firewall by selecting Originating traffic and
clicking the Apply Firewall button. By default, clicking
Apply Firewall will associate an SDM-default inspection
rule to the inbound direction of the From interface, andwill
associate an access rule to the inbound direction of the To
interface that denies traffic. If the Cisco IOS image that the
router is using does not support the Firewall feature, this
button is disabled.