Tripp Lite B098048 Owners Manual for B093- B097- and B098-Series Console Serve - Page 102

Tcp Or Udp, Tcp And Udp, Icmp, Esp, Gre

Page 102 highlights

5. Firewall, Failover and OOB Access Protocol Select if the firewall rule will apply to TCP or UDP, TCP and UDP, ICMP, ESP, GRE or Any. Direction Select the traffic direction the firewall rule will apply to (Ingress = incoming, or Egress). Action Select the action (Accept or Block) that will be applied to the detected packets that match the Interface + Port Range + Source/Destination Address Range + Protocol + Direction. For example, to block all SSH traffic from leaving Dial-Out Interface, the following settings can be used: Interface: Dial-Out/Cellular Port Range: 22 Protocol: TCP Direction: Egress Action: Block Firewall rules are processed in a set order- from top to bottom. As such, rule placement is important. For example, with the following rules, all incoming traffic over the Network Interface is blocked, except when it comes from two assigned IP addresses (SysAdmin and Tony): Interface Port Range Source MAC Source IP Destination IP Protocol Direction Action To allow all incoming traffic on all interfaces from the SysAdmin: Any Any Any IP address of SysAdmin Any TCP Ingress Accept To allow all incoming traffic from Tony: Any Any Any IP address of Tony Any TCP Ingress Accept To block all incoming traffic from the Network Interface: Network Interface Any Any Any Any TCP Ingress Block However, if the above Rule Order changed so the "Block Everyone Else" rule was second on the list, then the incoming traffic over the network interface from Tony would be blocked. 102

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288

102
5. Firewall, Failover and OOB Access
Protocol
Select if the firewall rule will apply to
TCP or UDP, TCP and UDP, ICMP, ESP, GRE
or
Any
.
Direction
Select the traffic direction the firewall rule will apply to
(Ingress = incoming
, or
Egress
).
Action
Select the action (
Accept
or
Block
) that will be applied to the detected packets that match the
Interface + Port Range + Source/Destination Address Range + Protocol + Direction.
For example, to block all SSH traffic from leaving Dial-Out Interface, the following settings can be used:
Interface: Dial-Out/Cellular
Port Range: 22
Protocol: TCP
Direction: Egress
Action: Block
Firewall rules are processed in a set order- from top to bottom. As such, rule placement is important. For example, with
the following rules, all incoming traffic over the Network Interface is blocked, except when it comes from two assigned IP
addresses (SysAdmin and Tony):
To allow all incoming traffic on all
interfaces from the SysAdmin:
To allow all incoming traffic
from Tony:
To block all incoming traffic
from the Network Interface:
Interface
Any
Any
Network Interface
Port Range
Any
Any
Any
Source MAC
Any
Any
Any
Source IP
IP address of SysAdmin
IP address of Tony
Any
Destination IP
Any
Any
Any
Protocol
TCP
TCP
TCP
Direction
Ingress
Ingress
Ingress
Action
Accept
Accept
Block
However, if the above
Rule Order
changed so the “Block Everyone Else” rule was second on the list, then the incoming traffic
over the network interface from Tony would be blocked.