Lantronix X300 Series X300 Series User Guide Rev B - Page 161

Firewall Zones, Packet filtering actions

Page 161 highlights

11: Network Parameters Drop invalid packet Input Output Forward Description Check to drop the invalid packets that are not matching any active connection. Select to accept or reject the inbound traffic to all the interfaces. Select to accept or reject the outbound traffic from all the interfaces. Select to accept or reject the forwarded traffic from all the interfaces. Firewall Zones Two firewall zones, the LAN zone and WAN zone, are predefined in the gateway. All traffic from LAN to WAN has no restrictions but all incoming traffic from WAN source is blocked unless a port forwarding rule is set or unless a particular port is opened. A zone section groups one or more interfaces and serves as source or destination for forwarding, rules, and redirects. A zone is defined by the following rules:  Masquerade (NAT) of outgoing traffic (WAN) is controlled on a per zone basis on the outgoing interface.  INPUT rules describe what happens to traffic trying to reach the gateway through an interface in that zone.  OUTPUT rules zone describe what happens to traffic originating from the gateway going through an interface in that zone.  FORWARD rules describe what happens to traffic passing between different interfaces in that zone. Packet filtering actions  ACCEPT - traffic is allowed to pass as if there is no firewall in place. If the port at the destination is closed, a response will be returned as if a Reject rule is in place.  DROP - the firewall discards the packet and sends no response back to the source host that sent the packet. The source host will wait for a response until a timeout occurs and may attempt to retry the connection after timeout occurs.  REJECT - the firewall discards the packet and sends a response back to the source host that the port is closed. Doing so can hint to the source that packet filtering firewall is in place. In general, use REJECT to deny traffic from trusted hosts by gracefully informing them that traffic is not allowed to pass. Use DROP to deny traffic from untrusted hosts or when you don't want expose information about the destination host. To configure firewall zones: 1. Go to Network > Firewall. 2. To add and configure a new firewall zone, click Add. 3. To modify settings for an existing firewall zone, click Edit. 4. Enter or modify the firewall zone settings. See Table 11-25. 5. Click Save. X300 Series IoT Cellular Gateway User Guide 161

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216

11: Network
X300 Series IoT Cellular Gateway User Guide
161
Firewall Zones
Two firewall zones, the LAN zone and WAN zone, are predefined in the gateway. All traffic from
LAN to WAN has no restrictions but all incoming traffic from WAN source is blocked unless a port
forwarding rule is set or unless a particular port is opened.
A zone section groups one or more interfaces and serves as source or destination for forwarding,
rules, and redirects. A zone is defined by the following rules:
Masquerade (NAT) of outgoing traffic (WAN) is controlled on a per zone basis on the outgoing
interface.
INPUT rules describe what happens to traffic trying to reach the gateway through an interface
in that zone.
OUTPUT rules zone describe what happens to traffic originating from the gateway going
through an interface in that zone.
FORWARD rules describe what happens to traffic passing between different interfaces in that
zone.
Packet filtering actions
ACCEPT – traffic is allowed to pass as if there is no firewall in place. If the port at the
destination is closed, a response will be returned as if a Reject rule is in place.
DROP – the firewall discards the packet and sends no response back to the source host that
sent the packet. The source host will wait for a response until a timeout occurs and may
attempt to retry the connection after timeout occurs.
REJECT – the firewall discards the packet and sends a response back to the source host that
the port is closed. Doing so can hint to the source that packet filtering firewall is in place.
In general, use REJECT to deny traffic from trusted hosts by gracefully informing them that traffic
is not allowed to pass. Use DROP to deny traffic from untrusted hosts or when you don’t want
expose information about the destination host.
To configure firewall zones:
1.
Go to Network > Firewall.
2.
To add and configure a new firewall zone, click
Add
.
3.
To modify settings for an existing firewall zone, click
Edit
.
4.
Enter or modify the firewall zone settings. See
Table 11-25
.
5.
Click
Save
.
Drop invalid packet
Check to drop the invalid packets that are not matching any active
connection.
Input
Select to accept or reject the inbound traffic to all the interfaces.
Output
Select to accept or reject the outbound traffic from all the interfaces.
Forward
Select to accept or reject the forwarded traffic from all the interfaces.
Parameters
Description