46
|
Chapter 4:
Firewall Protection and Content Filtering
ProSafe Dual WAN Gigabit Firewall with SSL & IPsec VPN FVS336Gv2 Reference Manual
DNS so that external users can always find your network (see
“Configuring Dynamic DNS
(Optional)”
on page 26).
•
If the IP address of the local server PC is assigned by DHCP, it may change when the PC
is rebooted. To avoid this, use the Reserved IP address feature to keep the PC’s IP
address constant (see <pdf>“Configuring DHCP Address Reservation” on page 3-37).
•
Local PCs must access the local server using the server’s local LAN address. Attempts
by local PCs to access the server using the external WAN IP address will fail.
Note:
See
“Configuring Port Triggering”
on page 66 for yet another way to
allow certain types of inbound traffic that would otherwise be blocked
by the VPN firewall.
Table 4-4.
Inbound Rules
Item
Description
Service
Select the desired service or application to be covered by this rule. If the desired
service or application does not appear in the table, you must define it using the
Services screen (see
“Adding Customized Services”
on page 57).
Action
Select the desired action for packets covered by this rule:
•
BLOCK always
•
BLOCK by schedule, otherwise Allow
•
ALLOW always
•
ALLOW by schedule, otherwise Block
Note
: Any inbound traffic which is not allowed by rules you create will be blocked
by the Default rule.
Select Schedule
Select the desired time schedule (Schedule1, Schedule2, or Schedule3) that will
be used by this rule (see
“Setting a Schedule to Block or Allow Specific Traffic”
on page 61).
•
This drop-down list gets activated only when “BLOCK by schedule,
otherwise Allow” or “ALLOW by schedule, otherwise Block” is selected as
Action.
•
Use schedule screen to configure the time schedules.
Send to LAN Server
This field appears only with NAT routing (not classical routing). This LAN
address or range of LAN addresses determines which computer or computers
on your network are hosting this service rule. (You can also translate these
addresses to a port number.)
Translate to Port
Number
Check this box and enter a port number to assign the LAN Server to a different
service port number. Inbound traffic to the service port will have the destination
port number modified to the port number configured here.
WAN Destination IP
Address
Specifies the destination IP address applicable to incoming traffic.
This is the public IP address that will map to the internal LAN server; it can either
be the address of the WAN1 or WAN2 ports or another public IP address
.