HELP
TABLE OF CONTENTS

Access>Rules

The Access> Rules page allows you to create Network Access Rules to customize your firewall security. The SonicWALL evaluates the source IP address, the destination IP address, and the service type when determining whether to allow or deny traffic. Custom rules take precedence and override the SonicWALL default rules. By default, the SonicWALL blocks all traffic from the Internet to the LAN and allows all traffic from the LAN to the Internet. Custom rules can be created to modify the default rules. For example, rules can be created for the following purposes:

Alert! Use extreme caution when creating or deleting Network Access Rules as you an accidentally disable firewall protection or block access to the Internet.

Network Access Rules can be configured to apply to all users, authenticated users, the administrator, or on a per user basis.

Maximum Number of Rules by SonicWALL Model

The following lists the maximum number of rules supported by each SonicWALL Internet Security Appliance model.

GX Series: 300

PRO 300, PRO 330: 200

PRO 100, PRO 200, PRO 230: 100

TELE3, SOHO3: 100

TELE2, SOHO2, XPRS2, XPRS, PRO, PRO-VX: 100

Network Access Rule Logic List

It is important to fully consider the logic behind the new rule before it is added to the list. Use the following guidelines to help you evaluate the impact of a rule before adding it to the list:

  1. State the intent of the rule. For example, “This rule restricts all IRC access from the LAN to the Internet.”

  2. Is the intent of the rule to allow or deny traffic?

  3. What is the direction of the traffic? From the LAN to the WAN, or from the WAN to the LAN?

  4. List IP services affected by the rules.

  5. List the computers on the LAN affected by the rule.

  6. List the computers on the WAN affected by the rule. If allowing traffic from the WAN to the LAN, it is better to allow WAN traffic only to certain computers on the LAN.

  7. Does the rule prevent users from accessing critical resources on the Internet?

  8. Does the rule create any security vulnerabilities?

  9. Does the rule conflict with any existing rules?

Understanding the Access Rule Hierarchy

The rule hierarchy has two basic concepts:

  1. Specific rules override general rules:

  1. Equally specific Deny rules override Allow rules.

Rules are displayed in the Current Network Access Rules list from the most specific to the least specific, and rules at the top override rules listed below.

Current Network Access Rules

The Current Network Access Rules table displays all the current rules in force on the SonicWALL. The following describes the columns in the Current Network Access Rules table:

Managing Network Access Rules

Add New Rule

Clicking the Add New Rule button displays the Add Rule window for adding a new network access rule.

Restore Rules to Defaults

The SonicWALL default network access rules prevent malicious intrusions and attacks, block all inbound IP traffic and allow all outbound IP traffic. If the SonicWALL Network Access Rules have been modified or deleted, you can restore the default network access rules by clicking the Restore Rules to Defaults button. A message dialog appears. Click OK to erase all non-default network access rules.

Help Table of Contents