User manual

The Action specifies what to do if the rule matches.
Accept means to allow the traffic.
Drop means to disallow the traffic.
Reject means to disallow the traffic, but also send an ICMP port unreachable
message to the source IP address.
None means to perform no action for this rule. This is useful for a rule that logs
packets, but performs no other action.
Type controls which incoming and outgoing interface options are available.
Forward means filter forwarded packets only, i.e. packets traversing the
SnapGear unit. You can select both incoming and outgoing interfaces.
Input means filter packets destined for this unit. You can select only the incoming
interface.
Output means filter packets generated by this unit. You can select only the
outgoing interface.
The Incoming Interface is the interface/network port that the SnapGear unitreceived the
network traffic on. Set this to None to match traffic destined for the SnapGear unit itself.
145
Firewall