User manual
Firewall
95
Warning
Leaving Create a corresponding ACCEPT firewall rule will allow all traffic into and out
from the specified private address, i.e. the private address will no longer be shielded by
your CyberGuard SG appliance’s firewall.
Otherwise, you may manually create filter rules through Rules.
Rules
The Rules configuration page allows firewall experts to view the current firewall rules and
add custom iptables firewall rules. To access this page, click Rules in the Firewall
menu.
Note
Only experts on firewalls and iptables will be able to add effective custom firewall rules
(further reading can be found at http://www.netfilter.org/documentation/).
Configuring the CyberGuard SG appliance’s firewall via the Incoming Access and
Outgoing Access and Packet Filtering configuration pages is adequate for most
applications.
Refer to Appendix C – System Log for details on creating custom log rules using iptables.
Universal Plug and Play Gateway
The Universal Plug and Play (UPnP) Gateway allows UPnP capable applications and
devices to request port forwarding rules to be established on demand. This allows some
applications and devices that may not operate correctly behind the NAT firewall to
automatically work.
Warning
There is concern in the security community over the potential vulnerability that UPnP
gateways present. For maximum security disable the UPnP Gateway feature.