Quick Reference Guide
ProSafe Wireless-N VPN Firewall SRXN3205 Reference Manual
Firewall Security and Content Filtering 5-5
v1.0, January 2010
Whether or not DHCP is enabled, how the PCs will access the server’s LAN address impacts the
inbound rules. For example:
• If your external IP address is assigned dynamically by your ISP (DHCP enabled), the IP
address may change periodically as the DHCP lease expires. Consider using dynamic DNS so
that external users can always find your network (see “Configuring Dynamic DNS” on page 2-
12).
• If the IP address of the local server PC is assigned by DHCP, it may change when the PC is
rebooted. To avoid this, use the Reserved IP address feature to keep the PC’s IP address
constant (see “Configuring DHCP Address Reservation” on page 3-9).
• Local PCs must access the local server using the server’s local LAN address. Attempts by
local PCs to access the server using the external WAN IP address will fail.
Note: See “Configuring Port Triggering” on page 5-31 for yet another way to allow
certain types of inbound traffic that would otherwise be blocked by the
firewall.
Table 5-2. Inbound Rules
Item Description
Service Select the desired service or application to be covered by this rule. If the desired service
or application does not appear in the list, you must define it using the Services screen
(see “Adding Customized Services” on page 5-19).
Action Select the desired action for packets covered by this rule:
• BLOCK always
• BLOCK by schedule, otherwise Allow
• ALLOW always
• ALLOW by schedule, otherwise Block
Note: Any inbound traffic which is not allowed by rules you create will be blocked by the
Default rule.
Select Schedule Select the desired time schedule (Schedule1, Schedule2, or Schedule3) that will be used
by this rule (see “Setting Schedules to Block or Allow Specific Traffic” on page 5-24).
• This pull-down menu gets activated only when “BLOCK by schedule, otherwise Allow”
or “ALLOW by schedule, otherwise Block” is selected as Action.
• Use a Schedule screen to configure the time schedules.
Send to LAN
Server
This field appears only with NAT routing (not classical routing). This LAN address or
range of LAN addresses determines which computer or computers on your network are
hosting this service rule. (You can also translate these addresses to a port number.)










