Netopia 435 Reference Manual page 162

Isdn router
Table of Contents

Advertisement

Security
7-29
Basic Firewall's filters play the following roles.
Input filters 1 and 2: These block WAN-originated OpenWindows and
X-Windows sessions. Service origination requests for these protocols
use ports 2000 and 6000, respectively. Since these are greater than
1023, OpenWindows and X-Windows traffic would otherwise be
allowed by input filter 4. Input filters 1 and 2 must precede input filter
4; otherwise they would have no effect as filter 4 would have already
passed OpenWindows and X-Windows traffic.
Input filter 3: This filter explicitly passes all WAN-originated ICMP
traffic to permit devices on the WAN to ping devices on the LAN. Ping
is an Internet service that is useful for diagnostic purposes.
Input filters 4 and 5: These filters pass all TCP and UDP traffic,
respectively, when the destination port is greater than 1023. This type
of traffic generally does not allow a remote host to connect to the LAN
using one of the potentially intrusive Internet services, such as Telnet,
FTP, and WWW.
Output filter 1: This filter passes all outgoing traffic to make sure that
no outgoing connections from the LAN are blocked.
Basic Firewall is suitable for a LAN containing only client hosts that
wish to access servers on the WAN, not for a LAN containing servers
providing services to clients on the WAN. Basic Firewall's general
strategy is to explicitly pass WAN-originated TCP and UDP traffic to
ports greater than 1023. Ports lower than 1024 are the service
origination ports for various Internet services such as FTP, Telnet, and
the World Wide Web (WWW).
A more complicated filter set would be required to provide WAN
access to a LAN-based server. See
"Possible modifications,"
below,
for ways to allow remote hosts to use services provided by servers on
the LAN.
Possible modifications
You can modify the sample filter set Basic Firewall to allow incoming
traffic using the examples below. These modifications are not
intended to be combined. Each modification is to be the only one used
with Basic Firewall.

Advertisement

Table of Contents
loading

Table of Contents