DMZ Firewall Solution for the Express Router

Filter Function

9Allows DNS reply to the HTTP/FTP proxy server on the DMZ.

Two filters are required.

10

11Allows DNS reply to the SMTP server on the DMZ.

Two filters are required.

12

13Allows incoming mail (SMTP) from any host on the Internet to the DMZ.

Settings

Dest. address type:

Host

Dest. address:

193.84.251.2

Dest. port

> 1023

Src. address type:

All

Src. port:

= 21

Action:

Pass

Protocol:

TCP

TCP flags:

ACK

Dest. address type:

Host

Dest. address:

193.84.251.2

Dest. port

> 1023

Src. address type:

Host

Src. address:

194.25.6.4

Src. port:

= 53

Action:

Pass

Protocol:

UDP

Dest. address type:

Host

Dest. address:

193.84.251.2

Dest. port

> 1023

Src. address type:

Host

Src. address:

194.25.6.4

Src. port:

= 53

Action:

Pass

Protocol:

TCP

TCP flags:

ACK

Dest. address type:

Host

Dest. address:

193.84.251.3

Dest. port

> 1023

Src. address type:

Host

Src. address:

194.25.6.4

Src. port:

= 53

Action:

Pass

Protocol:

UDP

Dest. address type:

Host

Dest. address:

193.84.251.3

Dest. port

> 1023

Src. address type:

Host

Src. address:

194.25.6.4

Src. port:

= 53

Action:

Pass

Protocol:

TCP

TCP flags:

All

Dest. address type:

Host

Dest. address:

193.84.251.3

Dest. port

= 25

Src. address type:

All

Src. port:

> 1023

07-12-99

Version 1.0

26

Page 27
Image 27
Intel 9515, 9525, 9535 manual Udp