Configuring Firewall Filters (J-Web Procedure)
You configure firewall filters on EX Series switches to control traffic that enters ports on the switch or enters and exits VLANs on the network and Layer 3 (routed) interfaces. To configure a firewall filter you must configure the filter and then apply it to a port, VLAN, or Layer 3 interface.
To configure firewall filters settings using the J-Web interface:
- Select Configure > Security > Filters.
The Firewall Filter Configuration page displays a list of all configured port/VLAN or router filters and the ports or VLANs associated with a particular filter.
- Click one:
- Add—Select this option to create a new filter. Enter information as specified in Table 1.
- Edit—Select this option to edit an existing filter. Enter information as specified in Table 1.
- Delete—Select this option to delete a filter.
- Term Up—Select this option to move a term up in the filter term list.
- Term Down—Select this option to move a term down in the filter term list.
Table 1: Create a New Filter
Field |
Function |
Your Action |
---|---|---|
Filter tab |
||
Filter type |
Specifies the filter type: port/VLAN firewall filter or router firewall filter. |
Select the filter type. |
Filter name |
Specifies the name for the filter. |
Enter a name. |
Select terms to be part of the filter |
Specifies the terms to be associated with the filter. Add new terms or edit existing terms. |
Click Add to add new terms. Enter information as specified in Table 2 and Table 3. |
Association tab |
||
Port Associations |
Specifies the ports with which the filter is associated. Note: For a port/VLAN filter type, only Ingress direction is supported for port association. |
|
VLAN Associations |
Specifies the VLANs with which the filter is associated. Note: Because router firewall filters can be associated with ports only, this section is not displayed for a router firewall filter. |
|
Table 2: Create a New Term
Field |
Function |
Your Action |
---|---|---|
Term Name |
Specifies the name of the term. |
Enter a name. |
Protocols |
Specifies the protocols to be associated with the term. |
|
Source |
Specifies the source IP address, MAC address, and available ports. Note: MAC address is specified only for port/VLAN filters. |
To specify the IP address, click Add > IP and enter the IP address. To specify the MAC address, click Add > MAC and enter the MAC address. To specify the ports (interfaces), click Add > Ports and enter the port number. To delete the IP address, MAC address, or port details, select it and click Remove. |
Destination |
Specifies the destination IP address, MAC address, and available ports. Note: MAC address is specified only for port/VLAN filters. |
To specify the IP address, click Add > IP and enter the IP address. To specify the MAC address, click Add > MAC and enter the MAC address. To specify the ports (interfaces), click Add > Ports and enter the port number. To delete the IP address, MAC address, or port details, select it and click Remove. |
Action |
Specifies the packet action for the term. |
Select one:
|
More |
Specifies advanced configuration options for the filter. |
Select the match conditions as specified in Table 3. Select the packet action for the term as specified in Table 3. |
Table 3: Advanced Options for Terms