6.3 Definition of Custom Traffic Rules

Log matching packets — all packets matching with rule (permitted, denied or dropped, according to the rule definition) will be logged in the Filter log.

Log matching connections — all connections matching this rule will be logged in the Connection log (only for permit rules). Individual packets included in these connec- tions will not be logged.

Note: Connections cannot be logged for deny nor drop rules.

Translation

Source or/and destination IP address translation.

The source IP address translation can be also called IP masquerading or Internet con- nection sharing. The source (private) IP address is substituted by the IP address of the interface connected to the Internet in packets routed from the local network to the In- ternet. Therefore, the entire local network can access the Internet transparently, but it is externally considered as one host.

IP translation is defined as follows:

Figure 6.19 Traffic rule — source address translation

No Translation — source address is not modified. This option is set by default and it is not displayed within traffic rules.

Translate to IP address of outgoing interface WinRoute will translate the source address of an outgoing packet to the IP address of the network interface from where the packet will be forwarded.

Translate to IP address of interface — selection of an interface. IP address of the appropriate packet will be translated to the primary address of this interface. This option is relevant if the return path should be different than the upstream path.

Translate to IP address — an IP address to which the source address will be translated (i.e. secondary IP address of an interface connected to the Internet). If you only

103

Page 103
Image 103
Kerio Tech Firewall6 manual Translation, 103