52
6
INTERNET
SE
CURITY
DMS3-CTC-25-114 v1.0
6.2 Firewall
Introduction
The MediaAccess Gateway comes with an integrated firewall that helps you protect your network from attacks from the Internet.
This firewall has a number of predefined levels to allow you to adjust the firewall to your needs.
Predefined security levels
The MediaAccess Gateway has a number of predefined security levels. The following levels are available:
For IPv4 traffic:
Maximum Security (High):
Blocks all the applications including IP-driven voice applications (such as Gtalk, Skype) and P2P applications. Allows
Internet browsing, email, VPN, DNS and iTunes services.
Typical Security (Medium):
Blocks P2P applications and Ping to the MediaAccess Gateway, allows all other traffic.
Minimum Security (Low):
Allows all secure applications.
Custom Security (this is the default configuration for the IPv4 firewall):
Enables the Intrusion Detection System (IDS) and allows all traffic passing through the Gateway (from and to the Internet)
is allowed, but you are able to block specific applications.
For IPv6 traffic:
Typical Security (this is the default configuration of the IPv6 firewall):
Allows all traffic from home network to internet and blocks all unrelated traffic from internet to home network.
Custom Security:
Enables the Intrusion Detection System (IDS) and allows all traffic passing through the Gateway (from and to the Internet)
is allowed, but you are able to block specific applications.
Changing the security level
Proceed as follows:
1 Browse to the Admin Tool (http://192.168.0.1).
For more information, see “Accessing the Admin Tool” on page 25.
2 On the Gateway menu, click Firewall.
3 The Firewall page appears.
Under Firewall Security Level, select one of the predefined levels or select Custom Security to create a custom level.
4 Click Save Settings.
Although BlockAll will block all connections, some mandatory types of traffic such as DNS will still be relayed between
LAN and WAN by the MediaAccess Gateway.
The firewall levels only have impact on traffic passing through your MediaAccess Gateway. This means that the
handling of traffic directly appointed from and to the MediaAccess Gateway is independent of the selected firewall
level.