To edit a rule:
1. In the 'Edit Rule' column, select the rule that you want to edit.
2. Modify the fields as desired.
3. Click the Apply
4. To save the changes to flash memory, refer to ''
button to save the changes.
Saving Configuration'' 167 on page .
To activate a de-activated rule:
1. In the 'Edit Rule' column, select the de-activated rule that you want to activate.
2. Click the Activate
To de-activate an activated rule:
button; the rule is activated.
1. In the 'Edit Rule' column, select the activated rule that you want to de-activate..
2. Click the DeActivate
To delete a rule:
button; the rule is de-activated.
1. Select the radio button of the entry you want to activate.
2. Click the Delete Rule
3. To save the changes to flash memory, refer to ''
button; the rule is deleted.
Saving Configuration'' 167 on page .
Table 3-11: Internal Firewall Parameters
Parameter Description
Is Rule Active A read-only field indicating whether the rule is active or not.
Note:
Source IP
After device reset, all rules are active.
IP address (or DNS name) of source network, or a specific host.
[AccessList_Source_IP]
Subnet Mask IP network mask - 255.255.255.255 for a single host or the
appropriate value for the source IP addresses. The IP address of the
sender of the incoming packet is bitwise ANDed with this mask and
then compared to the field 'Source IP'.
[AccessList_Net_Mask]
Local Port Range
[AccessList_Start_Port]
The destination UDP/TCP ports (on this device) to which packets are
sent.
The valid range is 0 to 65535.
[AccessList_End_Port]
Note:
Protocol
When the protocol type isn't TCP or UDP, the entire range must
be provided.
The protocol type (e.g., UDP, TCP, ICMP, ESP or 'Any'), or the IANA
protocol number (in the range of 0 (Any) to 255).
[AccessList_Protocol]
Note:
Packet Size
This field also accepts the abbreviated strings 'SIP' and 'HTTP'.
Specifying these strings implies selection of the TCP or UDP
protocols, and the appropriate port numbers as defined on the device.
Maximum allowed packet size.
The valid range is 0 to 65535.
[AccessList_Packet_Size]
Note:
When filtering fragmented IP packets, this field relates to the
overall (re-assembled) packet size, and not to the size of each
fragment.