13.1 Access Methods
The web configurator is, by far, the most comprehensive firewall configuration tool your Prestige has to
offer. For this reason, it is recommended that you configure your firewall using the web configurator. SMT
screens allow you to activate the firewall. CLI commands provide limited configuration options and are only
recommended for advanced users, please refer to the appendix for firewall CLI commands.
13.2 Firewall Policies Overview
Firewall rules are grouped based on the direction of travel of packets to which they apply:
•
LAN to LAN/ Router
•
LAN to WAN
•
LAN to DMZ
By default, the Prestige's stateful packet inspection allows packets traveling in the following directions:
•
LAN to LAN/ Router
This allows computers on the LAN to manage the Prestige and communicate between networks or
subnets connected to the LAN interface.
•
LAN to WAN
•
LAN to DMZ
•
WAN to DMZ
•
DMZ to WAN
By default, the Prestige's stateful packet inspection blocks packets traveling in the following directions:
•
WAN to LAN
•
WAN to WAN/ Router
This prevents computers on the WAN from using the Prestige as a gateway to communicate with
other computers on the WAN and/or managing the Prestige.
•
DMZ to LAN
Firewall Screens
This chapter shows you how to configure your Prestige's firewall.
•
WAN to LAN
•
WAN to WAN/ Router
•
WAN to DMZ
Prestige 652H/HW Series User's Guide
Chapter 13
Firewall Screens
•
DMZ to LAN
•
DMZ to WAN
•
DMZ to DMZ/ Router
13-1