73
Used to make rule management easier
Restrict to address
family
Match traffic from selected address family only
Protocol of the packet that is being matched against traffic
rules.
Match traffic with selected ICMP type only
Match incoming traffic from this zone only
Match incoming traffic from these MACs only
Match incoming traffic from this IP or range only
Match incoming traffic originating from the given source
port or port range on the client host only
Device/Any
zone/LAN/VPN/WAN
Match forwarded traffic to the given destination zone only
Match forwarded traffic to the given destination IP address
or IP range only
Match forwarded traffic to the given destination port or
port range only
Drop/Accept/Reject + chain
+ additional rules
Action to be taken on the packet if it matches the rule. You
can also define additional options like limiting packet
volume, and defining to which chain the rule belongs