The Firewall Rules section of the Status box shows all the
firewall rules currently implemented on the VPN Client. The rules are arranged
in order of importance, with the highest importance at the top. All but the last
two rules are defined by the VPN administrator to allow inbound and outbound
traffic between the VPN Client and the secure gateway, as well as between the
VPN Client and the private networks with which it communicates. Because the
rules are implemented from the top down, the VPN Client enforces them before
trying the two CPP default rules at the bottom. This approach lets the traffic
flow to and from private networks.
The bottom two rules define the filter’s default actions, which
are to drop both inbound and outbound traffic. These rules are implemented only
if the traffic doesn’t match any of the preceding rules.
To see the full fields of a specific rule, click the first column
in the top half of the Firewall Rules: window; the selected rule is displayed in
the bottom half of the window.
A firewall rule includes the following fields and options:
The Stateful Firewall Process
In the stateful Cisco Integrated Client, firewall protocols
TCP, UDP, and ICMP automatically allow inbound responses to outbound packets. To
allow inbound responses to outbound packets for any other protocols, the network
administrator needs to define specific filters on the VPN Concentrator. These
are then passed down to the VPN Client the next time a session is
established.