Netgear SRX5308 SRX5308 Reference Manual - Page 139

Security, Port Triggering, After a PC has finished using a port triggering application

Page 139 highlights

ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 Reference Manual Once configured, port triggering operates as follows: 1. A PC makes an outgoing connection using a port number that is defined in the Port Triggering Rules table. 2. The VPN firewall records this connection, opens the additional incoming port or ports that are associated with the rule in the port triggering table, and associates them with the PC. 3. The remote system receives the PC's request and responds using the incoming port or ports that are associated with the rule in the port triggering table on the VPN firewall. 4. The VPN firewall matches the response to the previous request, and forwards the response to the PC. Without port triggering, the response from the external application would be treated as a new connection request rather than a response to a requests from the LAN network. As such, it would be handled in accordance with the inbound port forwarding rules, and most likely would be blocked. Note these restrictions on port triggering: • Only one PC can use a port triggering application at any time. • After a PC has finished using a port triggering application, there is a short time-out period before the application can be used by another PC. This time-out period is required so the VPN firewall can determine that the application has terminated. Note: For additional ways of allowing inbound traffic, see "Inbound Rules (Port Forwarding)" on page 4-6. To add a port triggering rule: 1. Select Security > Port Triggering from the menu. The Port Triggering screen displays. (See Figure 4-29 on page 4-50, which shows one rule in the Port Triggering Rule table as an example.) Firewall Protection v1.0, April 2010 4-49

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348
  • 349
  • 350
  • 351
  • 352
  • 353
  • 354
  • 355
  • 356
  • 357
  • 358
  • 359
  • 360
  • 361
  • 362
  • 363
  • 364
  • 365
  • 366
  • 367
  • 368
  • 369
  • 370
  • 371
  • 372
  • 373
  • 374
  • 375
  • 376
  • 377
  • 378
  • 379
  • 380
  • 381
  • 382
  • 383
  • 384

ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 Reference Manual
Firewall Protection
4-49
v1.0, April 2010
Once configured, port triggering operates as follows:
1.
A PC makes an outgoing connection using a port number that is defined in the Port Triggering
Rules table.
2.
The VPN firewall records this connection, opens the additional incoming port or ports that are
associated with the rule in the port triggering table, and associates them with the PC.
3.
The remote system receives the PC’s request and responds using the incoming port or ports
that are associated with the rule in the port triggering table on the VPN firewall.
4.
The VPN firewall matches the response to the previous request, and forwards the response to
the PC.
Without port triggering, the response from the external application would be treated as a new
connection request rather than a response to a requests from the LAN network. As such, it would
be handled in accordance with the inbound port forwarding rules, and most likely would be
blocked.
Note these restrictions on port triggering:
Only one PC can use a port triggering application at any time.
After a PC has finished using a port triggering application, there is a short time-out period
before the application can be used by another PC. This time-out period is required so the VPN
firewall can determine that the application has terminated.
To add a port triggering rule:
1.
Select
Security
>
Port Triggering
from the menu. The Port Triggering screen displays. (See
Figure 4-29 on page 4-50
, which shows one rule in the Port Triggering Rule table as an
example.)
Note:
For additional ways of allowing inbound traffic, see
“Inbound Rules (Port Forwarding)” on page 4-6
.