Configuring The Firewall For A Vpn In A Dmz - Siemens RUGGEDCOM ROX II User Manual

Cli
Hide thumbs Also See for RUGGEDCOM ROX II:
Table of Contents

Advertisement

Chapter 5
Setup and Configuration
NOTE
The IPsec protocol operates on UDP port 500, using protocols Authentication Header (AH) and
Encapsulation Security Payload (ESP) protocols. The firewall must be configured to accept this
traffic in order to allow the IPsec protocol.
Table: Example
Action
Accept
Accept
Accept
For more information about configuring rules, refer to
8.
Configure the following rule to allow traffic from openswan, the IPsec daemon, to enter the firewall:
NOTE
IPsec traffic arriving at the firewall is directed to openswan, the IPsec daemon. Openswan
decrypts the traffic and then forwards it back to the firewall on the same interface that originally
received it. A rule is required to allow traffic to enter the firewall from this interface.
Table: Example
Action
Accept
For more information about configuring rules, refer to
Section 5.17.7

Configuring the Firewall for a VPN in a DMZ

When the firewall needs to pass VPN traffic through to another device, such as a VPN device in a Demilitarized
Zone (DMZ), then a DMZ zone and special rules are required.
To configure the firewall for a VPN in a DMZ, do the following:
1.
Make sure a basic firewall has been configured. For more information about configuring a firewall, refer to
Section 5.17.3, "Adding a
2.
Make sure a zone called dmz exists. For more information about managing zones, refer to
"Managing
Zones".
3.
Configure rules with the following parameter settings for the UDP, Authentication Header (AH) and
Encapsulation Security Payload (ESP) protocols:
NOTE
The IPsec protocol operations on UDP port 500, using protocols Authentication Header (AH) and
Encapsulation Security Payload (ESP) protocols. The firewall must be configured to accept this
traffic in order to allow the IPsec protocol.
274
Source-Zone
Destination-Zone
net
fw
net
fw
net
fw
Source-Zone
Destination-Zone
vpn
loc
Firewall".
Protocol
ah
esp
udp
Section 5.17.14, "Managing
Protocol
Section 5.17.14, "Managing
Configuring the Firewall for a VPN in a DMZ
RUGGEDCOM ROX II
CLI User Guide
Dest-Port
500
Rules".
Dest-Port
Rules".
Section 5.17.8,

Advertisement

Table of Contents
loading

This manual is also suitable for:

Rx1500Rx1512Rx1501Rx1510Rx1511

Table of Contents