Netgear SRX5308 SRX5308 Reference Manual - Page 92

Administrator Tips, Using Rules to Block or Allow Specific Kinds of Traffic - remote management

Page 92 highlights

ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 Reference Manual Administrator Tips Consider the following operational items: 1. As an option, you can enable remote management if you have to manage distant sites from a central location (see "Configuring VPN Authentication Domains, Groups, and Users" on page 7-1 and "Configuring Remote Management Access" on page 8-10). 2. Although using rules (see "Using Rules to Block or Allow Specific Kinds of Traffic" on page 4-2) is the basic way of managing the traffic through your system, you can further refine your control using the following features and capabilities of the VPN firewall: - Groups and hosts (see "Managing Groups and Hosts (LAN Groups)" on page 3-14) - Services (see "Services-Based Rules" on page 4-3) - Schedules (see "Setting a Schedule to Block or Allow Specific Traffic" on page 4-40) - Source MAC filtering (see "Enabling Source MAC Filtering" on page 4-44) - Port triggering (see "Configuring Port Triggering" on page 4-48) 3. Some firewall settings might affect the performance of the VPN firewall. For more information, see "Performance Management" on page 8-1. 4. The firewall logs can be configured to log and then email dropped packet information and other information to a specified email address. For information about how to configure logging and notifications, see "Activating Notification of Events, Alerts, and Syslogs" on page 9-5. Using Rules to Block or Allow Specific Kinds of Traffic Firewall rules are used to block or allow specific traffic passing through from one side to the other. You can configure up to 600 rules on the VPN firewall. Inbound rules (WAN to LAN) restrict access by outsiders to private resources, selectively allowing only specific outside users to access specific resources. Outbound rules (LAN to WAN) determine what outside resources local users can have access to. A firewall has two default rules, one for inbound traffic and one for outbound. The default rules of the VPN firewall are: • Inbound. Block all access from outside except responses to requests from the LAN side. • Outbound. Allow all access from the LAN side to the outside. 4-2 Firewall Protection v1.0, April 2010

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348
  • 349
  • 350
  • 351
  • 352
  • 353
  • 354
  • 355
  • 356
  • 357
  • 358
  • 359
  • 360
  • 361
  • 362
  • 363
  • 364
  • 365
  • 366
  • 367
  • 368
  • 369
  • 370
  • 371
  • 372
  • 373
  • 374
  • 375
  • 376
  • 377
  • 378
  • 379
  • 380
  • 381
  • 382
  • 383
  • 384

ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 Reference Manual
4-2
Firewall Protection
v1.0, April 2010
Administrator Tips
Consider the following operational items:
1.
As an option, you can enable remote management if you have to manage distant sites from a
central location (see
“Configuring VPN Authentication Domains, Groups, and Users” on
page 7-1
and
“Configuring Remote Management Access” on page 8-10
).
2.
Although using rules (see
“Using Rules to Block or Allow Specific Kinds of Traffic” on
page 4-2
) is the basic way of managing the traffic through your system, you can further refine
your control using the following features and capabilities of the VPN firewall:
Groups and hosts (see
“Managing Groups and Hosts (LAN Groups)” on page 3-14
)
Services (see
“Services-Based Rules” on page 4-3
)
Schedules (see
“Setting a Schedule to Block or Allow Specific Traffic” on page 4-40
)
Source MAC filtering (see
“Enabling Source MAC Filtering” on page 4-44
)
Port triggering (see
“Configuring Port Triggering” on page 4-48
)
3.
Some firewall settings might affect the performance of the VPN firewall. For more
information, see
“Performance Management” on page 8-1
.
4.
The firewall logs can be configured to log and then email dropped packet information and
other information to a specified email address. For information about how to configure
logging and notifications, see
“Activating Notification of Events, Alerts, and Syslogs” on
page 9-5
.
Using Rules to Block or Allow Specific Kinds of Traffic
Firewall rules are used to block or allow specific traffic passing through from one side to the other.
You can configure up to 600 rules on the VPN firewall. Inbound rules (WAN to LAN) restrict
access by outsiders to private resources, selectively allowing only specific outside users to access
specific resources. Outbound rules (LAN to WAN) determine what outside resources local users
can have access to.
A firewall has two default rules, one for inbound traffic and one for outbound. The default rules of
the VPN firewall are:
Inbound
. Block all access from outside except responses to requests from the LAN side.
Outbound
. Allow all access from the LAN side to the outside.