ProSecure Unified Threat Management (UTM) Appliance

Table 28. Inbound rules overview

Setting

Description

Inbound Rules

 

 

 

Service

The service or application to be covered by this rule. If the service or

All rules

(also referred to as

application does not display in the list, you need to define it using the

 

Service Name)

Services screen (see Add Customized Services on page 163).

 

 

 

 

Action

The action for outgoing connections covered by this rule:

All rules

(also referred to as

BLOCK always

 

Filter)

ALLOW always

 

 

 

Note: Any inbound traffic that is not blocked by rules you create is

 

 

 

allowed by the default rule.

 

 

 

Note: ALLOW rules are useful only if the traffic is already covered

 

 

 

by a BLOCK rule. That is, you wish to allow a subset of traffic that is

 

 

 

currently blocked by another rule. Similarly, BLOCK rules are useful

 

 

 

only if the traffic is already covered by an ALLOW rule. That is, you

 

 

 

wish to block a subset of traffic that is currently allowed by another

 

 

 

rule.

 

Select Schedule

The time schedule that is used by this rule. By default, there is no

All rules

 

schedule assigned (that is, None is selected from the Schedule

 

 

drop-down list), and the rule is in effect permanently. For information

 

 

about creating schedules, see Set a Schedule to Block or Allow

 

 

Specific Traffic on page 177.

 

 

 

 

Send to LAN Server

The LAN server address determines which computer on your

LAN WAN rules

 

network is hosting this service rule. (You can also translate this

 

 

address to a port number.) The options are:

 

 

Single address. Enter the required address in the Start field to

 

 

 

apply the rule to a single device on your LAN.

 

 

Address range. Enter the required addresses in the Start and

 

 

 

End fields to apply the rule to a range of devices.

 

 

 

 

Send to DMZ Server

The DMZ server address determines which computer on your

DMZ WAN rules

 

network is hosting this service rule. (You can also translate this

 

 

address to a port number.)

 

 

 

 

Translate to Port

If you want to assign the LAN server or DMZ server to a specific port,

LAN WAN rules

Number

you can enable this setting and specify a port number.

DMZ WAN rules

 

 

 

WAN Destination IP

The settings that determine the destination IP address applicable to

LAN WAN rules

Address

incoming traffic. This is the public IP address that maps to the

DMZ WAN rules

 

internal LAN server.

 

 

On the multiple WAN port models, it can be either the address of a

 

 

WAN interface or another public IP address (when you have a

 

 

secondary WAN address configured). On the single WAN port

 

 

models, it can be either the address of the single WAN interface or

 

 

another public IP address (when you have a secondary WAN

 

 

address configured).

 

 

You can also enter an address range. Enter the required addresses

 

 

in the Start and End fields to apply the rule to a range of devices.

 

Firewall Protection

135

Page 135
Image 135
NETGEAR STM150EW-100NAS, UTM5EW-100NAS manual 135, Setting Description Inbound Rules