81
Chapter 5: Firewall, Failover and Out-of-Band
Therewallrulesareprocessedinasetorder-fromtoptobottom.Soruleplacementisimportant.Forexamplewiththe
followingrules,alltrafccominginovertheNetwork Interface is blocked except when it comes from two nominated IP
addresses(SysAdmin and Tony):
To allow all incoming traffic on all
interfaces from the SysAdmin:
To allow all incoming
traffic from Tony:
To block all incoming traffic
from the Network Interface:
Interface
Any Any NetworkInterface
Port Range
Any Any Any
Source MAC
Any Any Any
Source IP
IP address of SysAdmin IP address of Tony Any
Destination IP
Any Any Any
Protocol
TCP TCP TCP
Direction
Ingress Ingress Ingress
Action
Accept Accept Block
However,iftheRule Order abovewastobechangedsothe“Block Everyone Else”rulewassecondonthelist,thenthetrafc
coming in over the Network Interface from Tony would be blocked.