Cisco SA520-K9 Administration Guide - Page 110

Configuring a Firewall Rule for Inbound Traffic, Firewall Configuration

Page 110 highlights

Firewall Configuration Configuring Firewall Rules to Control Inbound and Outbound Traffic 4 STEP 5 For a LAN to WAN rule only, enter the following information in the Source NAT Settings area: • SNAT IP Type: Source Network Address Translation (SNAT) requires rewriting the source or destination IP address of incoming IP packets as they pass through the firewall. Choose one of the following options: - WAN Interface Address: Choose this option to use the IP address of the WAN interface. - Single Address: Choose this option to map outbound traffic to an external IP address (usually provided by your ISP), and select the IP alias configured for the WAN interface. If no IP alias is configured, the list is empty. STEP 6 Click Apply to save your settings. Configuring a Firewall Rule for Inbound Traffic This procedure explains how to configure a firewall rule for the following traffic flows: • From the WAN to the LAN • From the WAN to the DMZ • From the DMZ to the LAN If you want to allow incoming traffic, you must make the security appliance's WAN port IP address known to the public. This is called "exposing your host." However, this public IP address does not necessarily have to be your WAN address. The security appliance supports multiple public IP addresses on a single WAN interface. When you create your firewall rule, you can choose whether to associate the public service with the dedicated WAN address, the optional WAN address, or another IP address that your ISP has provided to you. For examples, see Firewall Rule Configuration Examples, page 114. NOTE In addition to configuring firewall rules, you can use the following methods to control inbound traffic: • You can prevent common types of attacks. For more information, see Configuring Attack Checks, page 118. Cisco SA500 Series Security Appliances Administration Guide 110

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240

Firewall Configuration
Configuring Firewall Rules to Control Inbound and Outbound Traffic
Cisco SA500 Series Security Appliances Administration Guide
110
4
STEP 5
For a LAN to WAN rule only, enter the following information in the
Source NAT
Settings
area:
SNAT IP Type:
Source Network Address Translation (SNAT) requires re-
writing the source or destination IP address of incoming IP packets as they
pass through the firewall. Choose one of the following options:
-
WAN Interface Address:
Choose this option to use the IP address of the
WAN interface.
-
Single Address:
Choose this option to map outbound traffic to an
external IP address (usually provided by your ISP), and select the IP alias
configured for the WAN interface. If no IP alias is configured, the list is
empty.
STEP
6
Click
Apply
to save your settings.
Configuring a Firewall Rule for Inbound Traffic
This procedure explains how to configure a firewall rule for the following traffic
flows:
From the WAN to the LAN
From the WAN to the DMZ
From the DMZ to the LAN
If you want to allow incoming traffic, you must make the security appliance’s WAN
port IP address known to the public. This is called “exposing your host.” However,
this public IP address does not necessarily have to be your WAN address. The
security appliance supports multiple public IP addresses on a single WAN
interface. When you create your firewall rule, you can choose whether to associate
the public service with the dedicated WAN address, the optional WAN address, or
another IP address that your ISP has provided to you.
For examples, see
Firewall Rule Configuration Examples, page 114
.
NOTE
In addition to configuring firewall rules, you can use the following methods to
control inbound traffic:
You can prevent common types of attacks. For more information, see
Configuring Attack Checks, page 118
.