UsingtheRouter’sWebInterface23
8. IntheSourcePortfield,typetheportthatistheoriginofthetraffic.TypeANYifthesourceportdoes
notmatter.
9. FromtheActiondropdownlist,selecttheactiontoperformonthetraffic.Youcanallowthetrafficto
beaccepted,rejected,loggedordropped.Acceptedpacketsareallowedtocontinuethroughthe
firewall.Droppedpacketsareremovedandnofurtherprocessingisperformedonthem.Rejected
packetsaredropped,andanerrormessageissenttothesourceofthepacket.Loggedpacketsare
loggedtothesystem'smainlogfilewiththerule'snameprependedasanidentifier(viewablefromthe
Statisticspage).Logrulesdonotaffectthepacket'sfate.
10. TheDirectionislockedtoOUTGOINGwhileusingtheOutboundTrafficwizard.
11. FromtheProtocoldropdownlist,selecttheprotocolofthetrafficthatisbeingfiltered.

AdvancedSettings

TheFirewall'sAdvancedSettingsmodeallowsuserstomanipulateDNAT,SNAT,andFilterrulesdirectly.DNAT
rulescanmanipulatethedestinationaddressandportofapacket;similarlySNATrulescanmanipulatethe
sourceaddressandportofapacket.
FilterrulesapplyanACCEPT,REJECT,DROP,orLOGactiontoapacket.DNAT,SNAT,andFilterrulescanbe
associatediftheyarenamedthesame.ThisassociationisrecognizedwithinthePortForwardingand
OutboundTrafficwizardsaccessedfromtheNormalSettingsmode,andallowstheassociatedrulestobe
viewedandeditedasaseries.
Settingupstaticroutes
TosetupamanuallyconfiguredmappingofanIPaddresstoanexthopdestinationfordatapackets:
1. FromFirewall,selectStaticRoutes.
2. Inthepanethatappears,clickAddRoute.
3. IntheNamefield,typethenameoftheroute.
4. IntheAddressfield,typetheremotenetworkIPaddressoftheremotelocation.
5. IntheMaskfield,typethenetworkmaskthatisassignedontheremotelocation.
6. IntheGatewayfield,typetheIPaddressoftheroutingdevicethatsupportstheremoteIPNetwork.
7. ClickFinish.