User's Manual

ISG50 User’s Guide 353
CHAPTER 23
Firewall
23.1 Overview
Use the firewall to block or allow services that use static port numbers. The firewall can also limit
the number of user sessions.
This figure shows the ISG50’s default firewall rules in action and demonstrates how stateful
inspection works. User 1 can initiate a Telnet session from within the LAN1 zone and responses to
this request are allowed. However, other Telnet traffic initiated from the WAN or DMZ zone and
destined for the LAN1 zone is blocked. Communications between the WAN and the DMZ zones are
allowed. The firewall allows VPN traffic between any of the networks.
Figure 233 Default Firewall Action
23.1.1 What You Can Do in this Chapter
•Use the Firewall screens (Section 23.2 on page 360) to enable or disable the firewall and
asymmetrical routes, and manage and configure firewall rules.
•Use the Session Limit screens (see Section 23.3 on page 364) to limit the number of concurrent
NAT/firewall sessions a client can use.
ISG