Differences

This shows you the differences between two versions of the page.

firewall:example_1 [2010/11/04 12:20]
tibor
firewall:example_1 [2010/11/04 12:46] (current)
tibor
Line 1: Line 1:
 +[[tutorial|Firewall rule tutorial]] example 1:
 +
====== Modifying a standard rule ====== ====== Modifying a standard rule ======
Line 4: Line 6:
| Incorrect editing of the firewall rules may cause security risks! | | Incorrect editing of the firewall rules may cause security risks! |
-**A good understanding of how firewall rules work can be achieved by marking checkboxes on the Security Profile pages, and examining what new rules they add to the firewall rules:**+**A good understanding of how firewall rules work can be achieved by marking checkboxes on the [[web GUI:Security Profile]] pages, and examining what new rules they add to the [[web GUI:firewall rules page|firewall rules]].**
Say you have a telnet server (192.168.0.10) that you want **only one** remote PC (11.50.17.69) on the Internet be able to access. Using the Security Profile page you can enable access of the Telnet server, but that allows all Internet PCs to access your server! Using the Security Profile page you cannot control firewall behaviour more precisely – but by editing the rules manually you can! Say you have a telnet server (192.168.0.10) that you want **only one** remote PC (11.50.17.69) on the Internet be able to access. Using the Security Profile page you can enable access of the Telnet server, but that allows all Internet PCs to access your server! Using the Security Profile page you cannot control firewall behaviour more precisely – but by editing the rules manually you can!
  - On the [[web GUI:security profile|Security Profile: High]] page, under "Allowed applications" mark the Telnet server checkbox, and enter 192.168.0.10 into the IP Address field. Click Apply.   - On the [[web GUI:security profile|Security Profile: High]] page, under "Allowed applications" mark the Telnet server checkbox, and enter 192.168.0.10 into the IP Address field. Click Apply.
-  - Now if you open the [[web GUI:firewall rules page]] and take a look at the **Incoming user** rules of your WAN interface (the interface that is "used as: outside", you will see that an extra rule has been added:+  - Now if you open the [[web GUI:firewall rules page]] and take a look at the **Incoming user** rules of your WAN interface (the interface that is "used as: outside"), you will see that an extra rule has been added:
| ...\\ (dport == sip'5060') && (proto == udp) //accept//\\ proto == udp && dport == dhcpc'68' //accept//\\ **(dport == telnet'23') && proto == tcp //modify// static daddr 192.168.0.10** | | ...\\ (dport == sip'5060') && (proto == udp) //accept//\\ proto == udp && dport == dhcpc'68' //accept//\\ **(dport == telnet'23') && proto == tcp //modify// static daddr 192.168.0.10** |
firewall/example_1.1288869659.txt.gz · Last modified: 2010/11/04 12:20 by tibor
CC Attribution-Noncommercial-Share Alike 3.0 Unported
www.chimeric.de Valid CSS Driven by DokuWiki do yourself a favour and use a real browser - get firefox!! Recent changes RSS feed Valid XHTML 1.0