[Contents] [Prev] [Next] [Index] [Report an Error]

Creating Firewall Exceptions for Stateless Firewalls

To create a firewall exception for a subscriber:

  1. Access the subscriber’s Firewall page.
  2. In the Firewall page, click Create Firewall Exception.

    The Create Exception dialog box appears. Figure 28 shows the appearance of the dialog box when Enterprise Manager Portal is set to Advanced mode.

    Figure 28: Create Exception Dialog Box for Stateless Firewalls

    Image g015816.gif

  3. Enter field values to configure the values for the firewall exception.

    See Fields for Exceptions to Stateless Firewalls in Enterprise Manager Portal.

    Which protocols you select determines which associated protocol fields are available for editing.

    Note: If a user changes the value for a protocol when the configuration level for the portal is set to Normal mode, values for the following fields may be deleted: TCP Flags, Fragmentation Flags, Fragmentation Offset, Packet Length, ICMP Type, and ICMP Code.

    If the value of a protocol is changed to the original setting, the portal restores the associated field values that were previously removed.

  4. Click Create.

    The Firewall page shows the exception configured. Figure 29 shows three exceptions configured for a brickwall firewall service. The exceptions appear in priority order.

    Figure 29: Firewall Page with Firewall Service Applied and Exceptions Configured

    Image g015817.gif

Fields for Exceptions to Stateless Firewalls in Enterprise Manager Portal

Use the fields in this topic to configure rules for exceptions to stateless firewalls.

Rule Name

IP Protocols

ToS Byte

Use an x to indicate a bit to be ignored.

Source IP Addresses

Source Ports

Destination IP Addresses

Destination Ports

TCP Flags

Fragmentation Flags

Fragment Offset

Packet Length

ICMP Type

The following list shows the symbolic name and associated numbers for ICMP types. The ICMP types are the same as those on JUNOS routing platforms with the addition of traceroute.

ICMP Code

Priority

Direction

Action

Enabled


[Contents] [Prev] [Next] [Index] [Report an Error]