23
Chapter 6: Security Tab
EdgeRouter
™
Lite User Guide
Ubiquiti Networks, Inc.
Configuration
Name
The name of this policy is displayed.
Description
Enter keywords to describe this policy.
Default action
All policies have a default action if the
packets do not match any rule. Select the appropriate
default action:
•
Drop
Packets are blocked with no message.
•
Reject
Packets are blocked, and an ICMP (Internet
Control Message Protocol) message is sent saying the
destination is unreachable.
•
Accept
Packets are allowed.
Default Log
Check this box to log packets that trigger the
default action.
Click
Save Ruleset
to apply your changes.
Interfaces
•
Interface
Select the appropriate interface from the
drop-down list.
•
Direction
Select the direction of the traffic flow.
-
in
Match inbound packets.
-
out
Match outbound packets.
-
local
Match local packets.
•
Add Interface
Click
Add Interface
to enter more
interfaces.
Click
Save Ruleset
to apply your changes.
Stats
A table displays the following statistics about each rule.
Click a column heading to sort by that heading.
Rule
The rules are applied in the order specified. The
number of the rule in this order is displayed.
Packets
The number of packets that triggered this rule is
displayed.
Bytes
The number of bytes that triggered this rule is
displayed.
Action
The action specified by this rule is displayed.
Description
The keywords you entered to describe this
rule are displayed.
Firewall Groups
Create groups organized by IP address, network address,
or port number.
All/Address/Network/Port
Add Group
To create a new group, click
Add Group
.
The
Create New Group
screen appears.
Complete the following:
•
Name
Enter a name for this group.
•
Description
Enter keywords to describe this group.
•
Group Type
Select the appropriate option:
-
Address Group
Define a group by IP address.
-
Network Group
Define a group by network address.
-
Port Group
Define a group by port numbers.
Click
Save
to apply your changes.
Search
Allows you to search for specific text. Begin
typing; there is no need to press
enter
. The results are
filtered in real time as soon as you type two or more
characters.
All/Address/Network/Port
Click the appropriate tab to
filter the groups as needed.
•
All
All groups are displayed by default.
•
Address
All of the address groups are displayed.
•
Network
All of the network groups are displayed.
•
Port
All of the port groups are displayed.