Filtering Incoming Traffic For A Custom Policy - Watchguard Firebox X20E User Manual

Firmware version 8.6 all firebox x edge e-series standard and wireless models
Hide thumbs Also See for Firebox X20E:
Table of Contents

Advertisement

Configuring Custom Packet Filter Policies
In the Policy Name text box, type the name for your policy.
5
From the Protocol Settings drop-down list, select TCP Port, UDP Port, or Protocol.
6
In the text box adjacent to the Port/Protocol drop-down list, type a port number or protocol
7
number. To use a single port, type a port number in the first text box. To use a range of ports,
type the lower port number in the first text box, and the higher port number in the second text
box.
An IP protocol number is not the same as a TCP or UDP port number. TCP is IP protocol number 6 and UDP
is IP protocol number 17. If you use an IP protocol that is not TCP or UDP, you must enter its number. IP
protocol numbers include: 47 for GRE (Generic Routing Encapsulation) and 50 for ESP (Encapsulated
Security Payload). Most settings are done with TCP or UDP ports. You can find a list of protocol numbers at
http://www.iana.org/assignments/protocol-numbers.
Click Add.
8
Repeat steps 6-8 until you have a list of all the ports and protocols that this policy uses. You can
9
add more than one port and more than one protocol for a custom policy. More ports and
protocols make the network less secure. Add only the ports and protocols that are necessary.

Filtering incoming traffic for a custom policy

These steps restrict incoming traffic for a policy to specified computers behind the firewall. Refer to the
subsequent section for information to control outgoing traffic.
From the Incoming Filter drop-down list, select Allow or Deny.
1
If you set the Incoming Filter to Allow, type the IP address of the service host. This is the
2
computer that receives the traffic.
If you redirect the policy to another port, type the port number in the text box adjacent to Port
3
Redirect.
For more information, see "Working with Firewall NAT" on page 142.
To limit incoming traffic from the external network to the service host, use the drop-down list to
4
select Host IP Address, Network IP Address, or Host Range.
98
Firebox X Edge e-Series

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents