130
11 INTERNET SECU
RITY
E-DOC-CTC-20100728-0008 v2.0
11.3 Firewall
Introduction
The Technicolor Gateway comes with an integrated firewall that helps you protect your network from attacks from the
Internet. This firewall has a number of predefined levels to allow you to adjusted the firewall to your needs.
The Firewall is disabled by default. This means that all traffic passing through the Technicolor Gateway (from and to the
Internet) is allowed.
Predefined security levels
The Technicolor Gateway has a number of predefined security levels. The following levels are available:
BlockAll:
All traffic from and to the Internet is blocked. Game and Application Sharing is not allowed by the firewall.
Standard:
All outgoing connections are allowed. All incoming connections are blocked, except for inbound connections assigned to
a local host via Game and Application Sharing.
Disabled:
All in- and outgoing traffic is allowed to pass through your Technicolor Gateway, including Game and Application
Sharing.
This is the default firewall level.
High
All outgoing connections are blocked, except for traffic from well-known protocols such as DNS, HTTP, HTTPS, FTP,
TELNET, IMAP and POP. All incoming connections are blocked.
Game and Application Sharing is not allowed.
Medium:
All outgoing connections are blocked except MS Windows protocols such as NetBIOS, RPC and SMB. All incoming
connections are blocked except inbound connections assigned to a local host via Game and Application Sharing.
Low:
All outgoing connections are allowed. All incoming connections are blocked, except for ICMP (Internet Control
Management Protocol) and inbound connections assigned to a local host via Game and Application Sharing.
Changing the security level
Proceed as follows:
1 Browse to the Technicolor Gateway GUI.
2 On the Toolbox menu, click Firewall.
3 The Firewall page appears. In the upper-right corner, click Configure.
4 Under Security Settings, select the security level of your choice and click Apply.
Creating your own security level
Proceed as follows:
1 In the Toolbox menu click Firewall.
Although BlockAll will block all connections, some mandatory types of traffic such as DNS will still be relayed
between LAN and WAN by the Technicolor Gateway.
The firewall levels only have impact on traffic passing through your Technicolor Gateway. This means that the
handling of traffic directly appointed from and to Technicolor Gateway is independent of the selected firewall level.
Protocol checks will be performed on all accepted connections, irrespective of the chosen level.