Cisco SA520-K9 Administration Guide - Page 104

Preliminary Tasks for Firewall Rules, Creating Custom Services

Page 104 highlights

Firewall Configuration Configuring Firewall Rules to Control Inbound and Outbound Traffic 4 • Port triggers This section includes these topics: • Preliminary Tasks for Firewall Rules • Configuring the Default Outbound Policy • Configuring a Firewall Rule for Outbound Traffic • Configuring a Firewall Rule for Inbound Traffic NOTE For detailed examples, see Firewall Rule Configuration Examples, page 114. Preliminary Tasks for Firewall Rules Depending on the firewall settings that you want to apply, you might need to complete these tasks before you can configure your firewall rule: • If you want to create rules that apply to custom services, first create the records for the services. See Creating Custom Services, page 104. • If you want to create rules that apply only on specified days and times, first create the schedules. See Creating Schedules for a Firewall Rules, page 105. • If you want to use additional public IP addresses (typically assigned by your ISP) for firewall rules other than the IP address configured on the WAN interface. See Configuring IP Aliases for WAN interfaces, page 106. Creating Custom Services The security appliance is configured with a long list of standard services that you can use to configure firewall rules and port forwarding rules. (See Appendix B, "Standard Services.") If you need to configure a firewall rule for a service that is not on the standard list, first you must identify the service by entering a name, specifying the type, and assigning the port range. Cisco SA500 Series Security Appliances Administration Guide 104

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240

Firewall Configuration
Configuring Firewall Rules to Control Inbound and Outbound Traffic
Cisco SA500 Series Security Appliances Administration Guide
104
4
Port triggers
This section includes these topics:
Preliminary Tasks for Firewall Rules
Configuring the Default Outbound Policy
Configuring a Firewall Rule for Outbound Traffic
Configuring a Firewall Rule for Inbound Traffic
NOTE
For detailed examples, see
Firewall Rule Configuration Examples, page 114
.
Preliminary Tasks for Firewall Rules
Depending on the firewall settings that you want to apply, you might need to
complete these tasks before you can configure your firewall rule:
If you want to create rules that apply to custom services, first create the
records for the services. See
Creating Custom Services, page 104
.
If you want to create rules that apply only on specified days and times, first
create the schedules. See
Creating Schedules for a Firewall Rules,
page 105
.
If you want to use additional public IP addresses (typically assigned by your
ISP) for firewall rules other than the IP address configured on the WAN
interface. See
Configuring IP Aliases for WAN interfaces, page 106
.
Creating Custom Services
The security appliance is configured with a long list of standard services that you
can use to configure firewall rules and port forwarding rules. (See
Appendix B,
“Standard Services.”
) If you need to configure a firewall rule for a service that is
not on the standard list, first you must identify the service by entering a name,
specifying the type, and assigning the port range.