Cisco WS-CE500 Administration Manual page 109

Sa500 series small business security appliances
Table of Contents

Advertisement

Firewall Configuration
Configuring Firewall Rules to Control Inbound and Outbound Traffic
Cisco SA500 Series Security Appliances Administration Guide
-
If the From Zone is the LAN, then the To Zone can be the public DMZ or
insecure WAN.
Service: Choose from a list of common services or a custom defined service.
For more information, see
Custom Services, page
Action: Choose how and when to apply the rule.
Select Schedule: If you choose one of the "by schedule" actions, choose a
schedule from the list.
For more information about schedules, see
Firewall Rules, page
Source Hosts: You can apply the rule to all users or you can specify users
by entering an IP address or address range.
-
If you choose Single Address, enter an IP address in the From field.
-
If you choose Address Range, enter the first address in the From field and
enter the last address in the To field.
Destination Hosts: You can apply the rule to all users or you can specify
users by entering an IP address or address range.
-
If you choose Single Address, enter an IP address in the From field.
-
If you choose Address Range, enter the first address in the From field and
enter the last address in the To field.
Log: You can choose whether or not to log the packets for this rule. Click
Never if you do not want to log the packets, or click Always to log the
packets.
QoS Priority: You can use this rule to prioritize traffic. Each priority level
corresponds to a Term of Service (ToS) value.
-
Normal-Service: ToS=0 (lowest QoS)
-
Minimize-Cost: ToS=1
-
Maximize-Reliability: ToS=2
-
Maximize-Throughput: ToS=4
-
Minimize-Delay: ToS=8 (highest QoS)
Appendix B, "Standard Services"
104.
105.
and
Creating Schedules for a
4
Creating
109

Advertisement

Table of Contents
loading

Table of Contents