Chapter 10 Firewall
LTE7410 User’s Guide
77
10.6 Firewall Technical Reference
This section provides some technical background information about the topics covered in this
chapter.
10.6.1 Firewall Rules Overview
Your customized rules take precedence and override the LTE Device’s default settings. The LTE
Device checks the source IP address, destination IP address and IP protocol type of network traffic
against the firewall rules (in the order you list them). When the traffic matches a rule, the LTE
Device takes the action specified in the rule.
Firewall rules are grouped based on the direction of travel of packets to which they apply:
By default, the LTE Device’s stateful packet inspection allows packets traveling in the following
directions:
•LAN to Router
These rules specify which computers on the LAN can manage the LTE Device (remote
management).
Note: You can also configure the remote management settings to allow only a specific
computer to manage the LTE Device.
UDP Packet Count This is the rate of new UDP half-open sessions per second that causes the firewall to
start deleting half-open sessions. When the rate of new connection attempts rises
above this number, the LTE Device deletes half-open sessions as required to
accommodate new connection attempts.
ICMP Echo-Request Threshold
ICMP Echo-Request
Count
This is the rate of new ICMP Echo-Request half-open sessions per second that causes
the firewall to start deleting half-open sessions. When the rate of new connection
attempts rises above this number, the LTE Device deletes half-open sessions as
required to accommodate new connection attempts.
Others
ICMP Redirect Select Enable to monitor for and block ICMP redirect attacks.
An ICMP redirect attack is one where forged ICMP redirect messages can force the
client device to route packets for certain connections through an attacker’s host.
DoS Log(Log Level:
DEBUG)
Select Enable to log DoS attacks. See LTE7410 User’s Guide for information on
viewing logs.
OK Click this to save your changes.
Back Click this to exit this screen without saving.
Table 29 Security > Firewall > DoS > Advanced (continued)
LABEL DESCRIPTION
•LAN to Router •WAN to LAN
• LAN to WAN • WAN to Router