User`s guide

344
Configuration Security > Firewall
All Digi TransPort routers incorporate a comprehensive firewall facility. A firewall is a
security system that is used to restrict the type of traffic that the router will transmit or
receive based on a combination of IP address, service type, protocol type, port number and
IP flags. Firewalls are used to minimise the risk of unauthorised access to the local network
resources by external users or to restrict the range of external resources to which local
users have access. A more detailed description of how firewalls operate on Digi routers is
given in the “Firewall Scripts” section. Refer to this section before attempting to implement
a firewall.
The rules governing the operation of the firewall are contained in a pseudo-file called
“fw.txt”. This file can be created either by using the controls in the web page described
below or by using a text editor on a PC and then loading the resulting file onto the router
using FTP or XMODEM. Digi Routers are shipped with a default fw.txt file that can be used
as the starting point for a custom firewall configuration.
Configuration of the firewall is carried out by using the table described below. There are
three other buttons that appear just below the table. Their use will also be described.
Since a default file is supplied, when this page loads it will show the rules in the default
“fw.txt” file. If “fw.txt” does not exist, a blank table will be shown.
Hits
The numbers that appear in this column of the table are the number of hits for the rule that
appears to the right.
#
This is non-editable and is simply the rule number.
Delete
Clicking this button deletes the rule that appears to its left.
Insert
These buttons are used to insert new lines. The insert buttons that appear alongside
existing rules insert new blank lines above the line on which they appear. The button at the
bottom creates a new blank line at the end of the table. (An empty table will only have the
one button at the bottom). To create a new rule, click the button at the point the new rule
should appear and a new text box should appear. Type the rule into the text box and once
complete, click the “ok” button. To abandon any changes click the “cancel” button. Once the
“ok” button has been clicked the firewall task will validate the rule and if valid, will add it
the table. If errors are detected, a warning message will be displayed, at which point the
rule may be edited or deleted.
Edit
These buttons that appear to the right of the rule open up the rule in an edit text box which
allows the text to be edited. Click on the “ok” button to commit the changes or “cancel” to
abandon the edit.
Reset Hit Counters
Clicking this button resets (to zero) all the rule hit counts that appear in the left-hand
column of the table.
Save
Clicking this button saves changes to the table to the “fw.txt” file. If the changes are not
saved using this button, they will be lost if the router is rebooted or loses power.