Page 126 / 210 Scroll up to view Page 121 - 125
030-300554 Rev. A
126
June 2008
Verizon FiOS Router (Model 9100EM)
User Guide
13.8
Advanced Filtering
If you select
Firewall Settings
in the top navigation menu and then select
Advanced Filtering
in the left submenu,
the following screen will appear.
Advanced filtering is designed to allow comprehensive control over the firewall's behavior. You can define specific
input and output rules, control the order of logically similar sets of rules and make a distinction between rules that
apply to WAN and LAN devices.
This screen is divided into two sections, one for Input Rule Sets and the other for Output Rule Sets, which are for
configuring inbound and outbound traffic, respectively. Each section comprises subsets, which can be grouped into
three main subjects:
Initial rules—rules defined here will be applied first, on all gateway devices.
Network device rules—rules can be defined per each gateway device.
Final rules—rules defined here will be applied last, on all gateway devices.
To add rules to Input or Output rules sets, click the adjacent
New Entry
link.
Page 127 / 210
030-300554 Rev. A
127
June 2008
Verizon FiOS Router (Model 9100EM)
User Guide
For example, if you clicked the
New Entry
link for input Network (Home/Office) Rules, the following screen will
appear.
Select one of the following operation settings:
Select
Drop
to drop packets.
Select
Reject
to drop packets, and to send TCP Reset or ICMP Host Unreachable packets to the sender.
Select
Accept Connection
to accept all packets related to this session.
Select
Accept Packet
to accept packets matching this rule only. Do not use Stateful Packet Inspection
(SPI) to automatically accept packets related to this session.
After you have entered the desired values, click
OK
to continue.
Page 128 / 210
030-300554 Rev. A
128
June 2008
Verizon FiOS Router (Model 9100EM)
User Guide
If you clicked
OK
, the following screen will appear. The rule is now active.
The order of the rules appearance represents both the order in which they were defined and the sequence
by which they will be applied. By clicking the Move Up and Move Down action icons, you can change this order
after your rules are already defined (without having to delete and then re-add them). After you click the desired icon,
the screen will refresh and display the change.
Page 129 / 210
030-300554 Rev. A
129
June 2008
Verizon FiOS Router (Model 9100EM)
User Guide
13.9
Security Log
If you select
Firewall Settings
in the top navigation menu and then select
Security Log
in the left submenu, the
following screen will appear.
This screen alerts you of noteworthy information sent to Router from the Internet. The screen can contain 1000
entries, but a maximum of 50 entries are displayed at a time. Once 1000 entries have been logged, the oldest entry is
removed to make space for the new entries as they occur. In this screen, do any of the following:
Click
Close
to close the security log screen.
Click
Clear
Log to remove all entries from the log.
Click
Save
to save the settings to a syslog server.
Click Settings to configure the security settings. Clicking this button opens a new window that contains
configuration options for selecting the information that you want logged.
Click
Refresh
to refresh the security log screen.
To configure the security log settings, click the
Settings
button.
Page 130 / 210
030-300554 Rev. A
130
June 2008
Verizon FiOS Router (Model 9100EM)
User Guide
If you clicked
Settings
, the following screen will appear. Select the desired settings by clicking the check boxes (a
checkmark will appear in the box when a setting is enabled). Then, click
Apply
to save the settings.
Select the types of activities for which you would like to have a log message generated:
Accepted Events
Accepted Incoming Connections
Write a log message for each successful attempt to establish an inbound
connection to the home network.
Accepted Outgoing Connections
Write a log message for each successful attempt to establish an outgoing
connection to the public network.
Blocked Events
All Blocked Connection Attempts
Write a log message for each blocked attempt to establish an inbound
connection to the home network or vice versa. You can enable logging of blocked packets of specific types
by disabling this option, and enabling some of the more specific options below it.
Specific Events
Specify the blocked events that should be monitored. Use this to monitor specific event
such as SynFlood. A log message will be generated if either the corresponding check-box is checked, or the
“All Blocked Connection Attempts” check-box is checked.
Other Events
Remote Administration Attempts
Write a log message for each remote-administration connection
attempt, whether successful or not.
Connection States
Provide extra information about every change in a connection opened by the firewall.
Use this option to track connection handling by the firewall and Application Level Gateways (ALGs).
Log Buffer
Prevent Log Overrun
Select this check box in order to stop logging firewall activities when the memory
allocated for the log fills up.

Rate

3.5 / 5 based on 2 votes.

Bookmark Our Site

Press Ctrl + D to add this site to your favorites!

Share
Top