User's Manual

Table Of Contents
Firewall
Configuring the Firewall Access Rules to Control Inbound and Outbound Traffic
Cisco ISA500 Series Integrated Security Appliance Administrator Guide 179
6
The default access behaviors for all predefined zones and new zones follow the
above settings depending on their security levels. For example, if you create a
new trusted zone called “Data”, a certain of firewall access rules are automatically
generated to permit or block the traffic from the Data zone to other zones or from
other zones to the Data zone. The permit or block action is determined by the
security levels of the From and To zones. For example, the traffic from the Data
zone to the predefined WAN zone is permitted, but the traffic from the Data zone to
the predefined LAN zone is blocked.
Use the Default Policy page to view the default firewall access settings for all
predefined zones.
STEP 1 Click Firewall -> ACL Rules -> Default Policy.
The Default Policy window opens. The default access settings for all predefined
zones are listed in the table.
STEP 2 To expand the default access settings for a specific zone, click the Expand button.
To hide the default access settings for a specific zone, click the Collapse button.
The following behaviors are predefined on the security appliance.
Public(50) Deny Deny Deny Permit Permit
GUEST(25) Deny Deny Deny Deny Permit
Untrust(0) Deny Deny Deny Deny Deny
From\To
Trusted(100) VPN(75) Public(50) GUEST(25) Untrust(0)
From \To
LAN VIOCE VPN SSLVPN DMZ GUEST WAN
LAN NA Deny Permit Permit Permit Permit Permit
VOICE Deny NA Permit Permit Permit Permit Permit
VPN Deny Deny NA Deny Permit Permit Permit
SSLVPN Deny Deny Deny NA Permit Permit Permit
DMZ Deny Deny Deny Deny NA Permit Permit
GUEST Deny Deny Deny Deny Deny NA Permit
WAN Deny Deny Deny Deny Deny Deny NA