Firewall Access Rule Configuration Examples - Cisco ISA500 Series Administration Manual

Integrated security appliance
Hide thumbs Also See for ISA500 Series:
Table of Contents

Advertisement

Firewall

Firewall Access Rule Configuration Examples

STEP 4
STEP 5
Firewall Access Rule Configuration Examples
STEP 1
STEP 2
STEP 3
Cisco ISA500 Series Integrated Security Appliance Administrator Guide
-
Specific Times: Choose this option if you want to keep the access rule
active at specific times. Specify the Start Time and End Time by
entering the hour and minute.
Click OK to save your settings.
Click Save to apply your settings.
This section provides some configuration examples on adding firewall access and
NAT rules.
Allowing Inbound traffic to an Internal FTP server using the WAN IP Address
User Case:
You host a FTP server on your LAN. You want to open the FTP server
to Internet by using the IP address of the WAN1 interface. The inbound traffic is
addressed to your WAN1 IP address but is directed to the FTP server.
Solution:
You can create a port forwarding rule or an Advanced NAT rule to open
the internal FTP server to Internet, and create a firewall access rule to allow the
access.
Set the IP address 172.39.202.101 to the WAN1 interface.
Create a host address object with the IP 192.168.1.100 called "InternalFTP".
Go to the Firewall -> NAT -> Port Forwarding page to create a port forwarding
rule as follows.
Original Service
Translated Service
Translated IP
WAN
WAN IP
Enable Port Forwarding
FTP-CONTROL
FTP-CONTROL
InternalFTP
WAN1
WAN1_IP
On
6
187

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

Isa550Isa570Isa570wIsa550w

Table of Contents