User Guide

Configuring the STPro
Firewall
Default STPro Firewall
configuration
17 Network Security - Firewalling
215 / 288
3EC 36231 ABAA TCZZA Ed. 01
17.6 Firewall Configuration
In order to create a Firewall, suitable for your needs, you can
create a chain on every hook at the STPro. In each chain rules
can be applied with configurable parameters. Rules can also refer
to a previously defined access list, thus allowing nested access
lists, or chains.
You can configure the STPro firewall only via the CLI.
See chapter 22 for more information.
The STPro Firewall is enabled by default with following behavior:
Packets migrating
from WAN to WAN are dropped
from STPro to WAN are dropped, except Port 53 (DNS)
from STPro to LAN are allowed
from LAN to STPro are allowed
from LAN to WAN are allowed
from WAN to LAN are allowed
from a remote LAN to local LAN are allowed
from local LAN to a remote LAN are allowed.