Quick Reference Guide
ProSafe Wireless-N VPN Firewall SRXN3205 Reference Manual
Firewall Security and Content Filtering 5-1
v1.0, January 2010
Chapter 5
Firewall Security and Content Filtering
This chapter describes how to set up your firewall and use the content filtering features of the
ProSafe Wireless-N VPN Firewall SRXN3205 to protect your network.
This chapter contains the following sections:
• “About Firewall Security and Content Filtering” on this page
• “Using Rules & Services to Block or Allow Traffic” on page 5-2
• “Configuring Other Firewall Features” on page 5-14
• “Creating Services, QoS Profiles, and Bandwidth Profiles” on page 5-19
• “Blocking Internet Sites (Content Filtering)” on page 5-25
• “Enabling Source MAC Filtering (Address Filtering)” on page 5-28
• “Configuring IP/MAC Address Binding” on page 5-29
• “Configuring Port Triggering” on page 5-31
• “Configuring UPnP (Universal Plug and Play)” on page 5-34
• “E-Mail Notifications of Event Logs and Alerts” on page 5-35
• “Administrator Tips” on page 5-36
About Firewall Security and Content Filtering
The VPN firewall provides you with Web content filtering options, plus browsing activity
reporting and instant alerts via e-mail. Network administrators can establish restricted access
policies based on time-of-day, Web addresses, and Web address keywords. You can also block
Internet access by applications and services, such as chat or games.
A firewall is a special category of router that protects one network (the “trusted” network, such as
your LAN) from another (the untrusted network, such as the Internet), while allowing
communication between the two. You can further segment keyword blocking to certain known
groups (see “Managing Groups and Hosts (LAN Groups)” on page 3-5 to set up LAN Groups).
A firewall incorporates the functions of a NAT (Network Address Translation) router, while
adding features for dealing with a hacker intrusion or attack, and for controlling the types of traffic
that can flow between the two networks. Unlike simple Internet sharing NAT routers, a firewall










