User guide

Firewall Configuration
64 (98) EN/LZT 108 6492 R1
April 2003
Field Description
Src IP Address IP address critera for the source computer(s) from which the
packet originates. Use the following expressions to specify IP:
any: any source IP address
lt: less than
lteq: less than or equal to
gt: greater than
eq: equal to
neq: not equal to
range: within the specified range, inclusive
out of range: outside the specified range
self: the IP address of the router interface on which this rule
takes effect.
Dest IP Address IP address rule criteria for the destination computer(s), i.e. the
IP address of the computer to which the packet is being sent.
In addition to the options described for the Src IP Address
field, the following option is available:
bcast: Specifies that the rule will be invoked for any packets
sent to the broadcast address for the receiving interface. (The
broadcast address is used to send packets to all hosts on the
LAN or subnet connected to the specified interface). When you
select this option, you do not need to specify the address, so the
address fields are dimmed.
Protocol The basic IP protocol criteria that must be met for a rule to be
invoked. Using the options in the drop-down list, you can
specify that packets must contain the selected protocol (eq),
that they must not contain the specified protocol (neq), or that
the rule can be invoked regardless of the protocol (any). TCP,
UDP and ICMP are commonly IP protocols; others can be
identified by number from 0-255 as defined by IANA.
Apply Stateful Inspection If this option is enabled, then stateful filtering is performed
and the rule is also applied in the other direction on the given
interface during an IP session.
Source Port Port number criteria for the computer(s) from which the packet
originates. This field will be dimmed (unavailable for entry) if
you have not specified a protocol critera. See the description of
Src IP Address for the selection options.
Dest Port Port number criteria for the destination computer(s), i.e. the
port number of the type of computer to which the packet is
being sent. This field will be dimmed (unavailable for entry)
unless you have selected TCP or UDP as the protocol. See the
description of Src IP Address for the selection options.