Kerio Tech Firewall6 Network Router User Manual


 
Chapter 6 Traffic Policy
96
6.2 How traffic rules work
The traffic policy consists of rules ordered by their priority. When the rules are applied
they are processed from the top downwards and the first suitable rule found is applied.
The order of the rules can be changed with the two arrow buttons on the right side of
the window.
An explicit rule denying all traffic is shown at the end of the list. This rule cannot be
edited or removed. If there is no rule to allow particular network traffic, then the “catch
all” deny rule will discard the packet.
Notes:
1. Unless any other traffic rules are defined (by hand or using the wizard), all traffic is
blocked by a special rule which is set as default.
2. To control user connections to WWW or FTP servers, use the special tools available
in WinRoute (see chapter 10) rather than traffic rules.
6.3 Definition of Custom Traffic Rules
The traffic rules are displayed in the form of a table, where each rule is represented
by a row and rule properties (name, conditions, actions for details see below) are
described in the columns. Left-click in a selected field of the table (or right-click a rule
and choose the Edit... option in the context menu) to open a dialog where the selected
item can be edited.
To define new rules press the Add button. Move the new rule within the list using the
arrow buttons.
Name
Name of the rule. It should be brief and unique. More detailed information can be
included in the Description entry.
Matching fields next to names can be either ticked to activate or unticked to disable. If
a particular field is empty, WinRoute will ignore the rule. This means that you need not
remove and later redefine these rules when troubleshooting a rule.
The background color of each row can be defined as well. Use the Transparent option
to make the background transparent (background color of the whole list will be used,
white is usually set).
Any text describing the particular rule may be used to specify the Description entry (up
to 1024 characters).