98 SMG digital gateway
Name—rule name.
Enable—defines whether the rule is used. When
unchecked, the rule is inactive.
Traffic type—type of traffic for the rule being created:
– egress—intended for SMG;
– ingress—sent by SMG.
Packet source—defines the network address of the
packet source either for all addresses or for a
particular IP address or network:
– any—for all addresses (the checkbox is
checked);
– IP address/mask—for a particular IP address
or network. The field is active when the any
checkbox is unchecked. The mask is
mandatory for a network, but optional for an
IP address.
Source ports—a ТСР/UDP port or port range (defined with a hyphen "-") of the packet source. This
parameter is used for TCP and UDP only; thus, select UDP, TCP, or TCP/UDP in this field to make it
active.
Destination address—defines the network address of the packet recipient either for all addresses
or for a particular IP address or network:
– any—for all addresses (the checkbox is checked);
– IP address/mask—for a particular IP address or network. The field is active when the any
checkbox is unchecked. The mask is mandatory for a network, but optional for an IP
address.
Destination ports—a ТСР/UDP port or port range (defined with a hyphen "-") of the packet
recipient. This parameter is used for TCP and UDP only; thus, select UDP, TCP, or TCP/UDP in this
field to make it active.
Protocol—the protocol the rule will be used for: UDP, TCP, ICMP, or TCP/UDP.
ICMP Message type—the ICMP message type the rule will be used for. This field is active, when
ICMP is selected in the Protocol field.
Action—an action executed by the rule:
– ACCEPT—the packets corresponding this rule will be accepted by the firewall.
– DROP—the packets corresponding this rule will be rejected by the firewall without
informing the party that has sent them.
– REJECT—the packets corresponding this rule will be rejected by the firewall. The party
that has sent the packet will receive either a TCP RST packet or "ICMP destination
unreachable".
A created rule is placed into the corresponding section: "Incoming traffic rules", "Outgoing traffic rules" or
"Transit traffic rules".
Also, the firewall profile allows specification of the network interfaces the rules of the profile will be
applied to.