Chapter 24 Firewall

4Don't enable any local service (such as NTP) that you don't use. Any enabled service could present a potential security risk. A determined hacker might be able to find creative ways to misuse the enabled services to access the firewall or the network.

5For local services that are enabled, protect against misuse. Protect by configuring the services to communicate only with specific peers, and protect by configuring rules to block packets for the services at specific interfaces.

6Protect against IP spoofing by making sure the firewall is active.7Keep the firewall in a secured (locked) room.

24.2General

Use this screen to enable or disable the NBG4615’s firewall, and set up firewall logs. Click Security > Firewall to open the General screen.

Figure 120 Security > Firewall > General l

The following table describes the labels in this screen.

Table 75 Security > Firewall > General

LABEL

DESCRIPTION

Enable FirewallSelect this check box to activate the firewall. The NBG4615 performs access

 

control and protects against Denial of Service (DoS) attacks when the firewall is

 

activated.

 

 

Apply

Click Apply to save the settings.

 

 

Cancel

Click Cancel to start configuring this screen again.

 

 

24.3 Services

If an outside user attempts to probe an unsupported port on your NBG4615, an ICMP response packet is automatically returned. This allows the outside user to know the NBG4615 exists. Use this screen to prevent the ICMP response packet from being sent. This keeps outsiders from discovering your NBG4615 when unsupported ports are probed.

You can also use this screen to enable service blocking, enter/delete/modify the services you want to block and the date/time you want to block them.

 

187

NBG4615 User’s Guide