Configuring Stateful Firewall (NSM Procedure)
Stateful firewall is a type of firewall filter that considers
state information derived from previous communications and other applications
when evaluating traffic. Contrasted with a stateless firewall that
inspects packets in isolation, a stateful firewall provides an extra
layer of security by using state information derived from past communications
and other applications to make dynamic control decisions for new communication
attempts.
To configure stateful firewall in NSM:
- In the navigation tree select Device Manager > Devices.
- In the Devices list, double-click
the device to select it.
- In the Configuration tab,
expand Services > Stateful Firewall.
- Add or modify the settings as specified in Table 1.
- Click one:
- OK—To save the changes.
- Cancel—To cancel the modifications.
Table 1: Stateful Firewall Configuration Details
| Task |
Your Action |
Define the rule.
|
- Click Rule next to Stateful
Firewall.
- Click Add new entry next to
Rule.
- In the Name box, enter the
identifier for the collection of terms that constitute this rule.
- In the Comment box, enter
the comment.
- From the Match Direction list,
select the direction in which the rule match is applied.
- Select input to apply the rule match
on the input side of the interface.
- Select output to apply the rule match
on the output side of the interface.
- Select input-output to apply the
rule match bidirectionally.
- Click Term next to rule.
- Click Add new entry next to
Term.
- In the Name box, enter the
identifier for the term.
- In the Comment box, enter
the comment.
- Expand term.
- Click From next to term.
- In the Comment box, enter
the comment.
- Expand From.
- From the listed match conditions, select the match
condition for stateful firewall.
The match conditions listed are Application Sets, Applications,
Destination Address, Destination Address Range, Destination Prefix
List, Source Address, Source Address Range, and Source Prefix List.
- Click Then next to term.
- In the Comment box, enter
the comment.
- Select the Syslog check box
to enable system logging.
- Expand Then.
- Click Accept next to Then.
- Select Accept to accept the traffic
and send it on to its destination.
- Select discard to not accept traffic
or process it further.
- Select reject to accept the traffic
and return a rejection message.
- Click Allow Ip Options next to Then.
- Click Add new entry next to
Allow Ip Options.
- From the dropdown list, select the IP option name.
|
Define the rule set.
|
- Click Rule Set next to
Stateful Firewall.
- Click Add new entry next to
Rule Set.
- In the Name box, enter the
identifier for the collection of rules that constitute this rule set.
- In the Comment box, enter
the comment.
- Click Rule next to rule-set.
- Click Add new entry next to
Rule.
- From the Name list, select
the identifier for the collection of terms that constitute this rule.
- In the Comment box, enter
the comment.
|
Published: 2009-08-23