12.0

Table Of Contents
Table 14-2
Firewall rule parameters (continued)
DescriptionParameter
The network services that trigger a rule.
A network service is a collection of the protocols and the port numbers
that are grouped under one name. The network services list contains
commonly used network services. For example, HTTP Server is the name
for the HTTP server traffic that uses TCP local ports 80 and 443. DHCP
Server is the name for the DHCP server traffic that uses UDP ports 67
and 68.
When you define TCP or UDP service triggers, you identify the ports on
both sides of the network connection. The port relationship is
independent of the traffic direction. The local computer owns the local
port. The remote computer owns the remote port.
Service
This parameter specifies whether Symantec Protection Center records
successful and unsuccessful network connection attempts.
The choices are as follows:
Yes
The server records the network connection.
No
The server does not record the network connection.
Send Email Alert
An email notification is sent. You must configure the notification.
See Creating a notification on page 98.
Log
About firewall rules and stateful inspection
Firewall protection uses stateful inspection to track current connections. Stateful
inspection tracks source and destination IP addresses, ports, applications, and
other connection information. Before the client inspects the firewall rules, it
makes the traffic flow decisions that are based on the connection information.
For example, if a firewall rule allows a computer to connect to a Web server, the
firewall logs the connection information. When the server replies, the firewall
discovers that a response from the Web server to the computer is expected. It
permits the Web server traffic to flow to the initiating computer without inspecting
the rule base. A rule must permit the initial outbound traffic before the firewall
logs the connection.
Stateful inspection simplifies rule bases. For the traffic that is initiated in one
direction, you do not have to create the rules that permit the traffic in both
directions. The client traffic that is initiated in one direction includes Telnet (port
Managing firewall protection
How the firewall works
132