ProSecure Unified Threat Management (UTM) Appliance

When a new connection is established by a device, the device locates the firewall rule corresponding to the connection.

If the rule has a bandwidth profile specification, the device creates a bandwidth class in the kernel.

If multiple connections correspond to the same firewall rule, the connections all share the same bandwidth class.

An exception occurs for an individual bandwidth profile if the classes are per-source IP address classes. The source IP address is the IP address of the first packet that is transmitted for the connection. So for outbound firewall rules, the source IP address is the LAN-side IP address; for inbound firewall rules, the source IP address is the WAN-side IP address. The class is deleted when all the connections that are using the class expire.

After you have created a bandwidth profile, you can assign the profile to firewall rules and application control profiles on the following screens:

Add LAN WAN Outbound Services screen (see Figure 68 on page 141).

Add LAN WAN Inbound Services screen (see Figure 69 on page 142).

Application Control Policy pop-up screens (see Figure 136 on page 245 and Figure 137 on page 245). You can access these pop-up screens from the Add or Edit Application Control Profile screen (see Figure 135 on page 243).

To add and enable a bandwidth profile:

1. Select Network Security > Services > Bandwidth Profiles. The Bandwidth Profiles screen displays. (The following figure shows one user-defined profile in the List of Bandwidth Profiles table as an example.)

Figure 95.

2.Under the List of Bandwidth Profiles table, click the Add table button. The Add Bandwidth Profile screen displays:

Firewall Protection

172

Page 172
Image 172
NETGEAR UTM5EW-100NAS, STM150EW-100NAS manual  To add and enable a bandwidth profile, 172