Firewall configuration, also known as IP filtering, refers to the selective blocking of the passage of IP packets between global and local networks. The filtering is based on rules that describe the characteristics of the packet. For example, the contents of the IP header, the input/output interface or the protocol.
You can use the Firewall Configuration form to enable a firewall on the console server. You can define rules to allow or disallow packets and configure filtering of packets that are sent and received through console server.
By default the list has three built-in chains, as shown in the previous figure. The chains accept all INPUT, FORWARD and OUTPUT packets. You can use the
Edit,
Delete,
Add and
Edit Rules buttons on the form to perform the following to configure packet filtering:
Selecting one of the default chains and pressing the Edit button, the Edit Chain dialog box shown in the following figure appears.
If the Add button is pressed under, the Add Chain dialog box shown in the following figure appears.
If the Edit Rules button is pressed, a form appears with a list of headings like the one shown in the following figure. The example shows the OUTPUT chain selected for editing.
The Add Rule and
Edit Rule dialog boxes have the fields and options shown in the following figure.
If the Inverted checkbox is enabled for the corresponding option, the target action is performed on packets that do not match any of the criteria specified in that line.
For example, you select DROP as the target action from the Target pull-down list, check Inverted on the line with the Source IP and do not specify any other criteria in the rule, any packets arriving from any other source IP address than the one specified are dropped.
The Target pull-down menu shows the action to be performed on an IP packet that matches all the criteria specified in a rule. The kernel can be configured to
ACCEPT,
DROP,
RETURN,
LOG or
REJECT the packet by sending a message, translating the source or the destination IP address or sending the packet to another user-defined chain.
If you add a value in the Source IP field, incoming packets are filtered for the specified IP address and if you add a value in the Destination IP field, outgoing packets are filtered for the specified IP address. A value in the Mask field means incoming or outgoing packets are filtered for IP addresses from the network in the specified subnet.
If Numeric is selected as the protocol when specifying a rule, a text field appears to the right of the menu for the desired number.
If ICMP is selected as a protocol, the ICMP Type pull-down menu is displayed in the ICMP Options Section at the bottom of the Firewall Configuration form. Select the ICMP type needed from the list.
If an interface (such as eth0 or eth1) is entered in the Input Interface field, incoming packets are filtered for the specified interface. If an interface is entered in the Output Interface field, outgoing packets are filtered for the specified interface. The input and output interface fields are shown in the following figure along with the options on the Fragments pull-down menu.
If you select LOG from the Target field, the fields and menus shown in the following figure appear in the LOG Options Section at the bottom of the form.
If REJECT is selected from the Target pull-down menu, the following pull-down menu appears.
Any Reject with option causes the input packet to be dropped and a reply packet of the specified type to be sent.