Firewall

The Firewall page allows you to define rules for incoming traffic from the Internet and outgoing traffic from within the site.

By default, all incoming traffic is blocked and all outgoing traffic is allowed.

The following policies can be configured to manage the firewall:

  • Application Access—Allows or blocks applications that can be used on the network.
  • Client Access—Controls destinations that can be reached by clients on the network.
  • Network Access—Controls destinations that can be reached from this network.
  • Remote Access—Allows or blocks port forwarding during specific times.

To configure one or more policies for the firewall, click the View policies. You will be redirected to the Policies page.

To view the configured firewall policies, click the policy name or number of policies (in the case of two or more policies) hyperlink below Controlled by. You will be redirected to the Policies page. The Policies page is filtered to only show the firewall policies.

For more information on creating policies, see Policies.

Application Layer gateway (ALG)

The Application Layer Gateway (ALG) section lets you control which protocol helpers the secure gateway uses to inspect and rewrite protocol-specific traffic so it can traverse NAT. ALG helpers are enabled by default and benefit most networks. In some deployments a helper can interfere with applications that perform their own NAT traversal—for example, a VoIP provider using STUN/TURN/ICE—so you can disable individual protocols for troubleshooting.This section is available only on sites with a secure gateway and applies to every LAN network on the site.

Under Protocols, select or clear the checkbox for each protocol to enable or disable its ALG helper. All protocols are enabled by default.

The following policies can be configured to manage the firewall:

  • Session Initiation Protocol (SIP)—Manages voice and video signaling. Disabling may lead to silent calls or dropped connections.
  • H.323—Handles legacy video conferencing traffic. Disabling may lead to failed calls or one-way audio.
  • Real-Time Streaming Protocol (RTSP)—Controls media streams for cameras and players. Disabling may lead to frozen video or broken playback.
  • File Transfer Protocol (FTP)—Coordinates data exchange between clients and servers. Disabling may lead to timed-out transfers or hidden file lists.
  • Trivial File Transfer Protocol (TFTP)—Supports simple file transfers for device booting and configuration updates. Disabling may lead to firmware update or PXE boot failures.

Changes are applied to the secure gateway without rebooting the device. Because existing sessions continue under their previous behavior, HPE recommends restarting the firewall (see Restart Firewall) so the change also takes effect on active session.

Restart Firewall

Whenever a new policy is created or an Application Layer Gateway (ALG) protocol is enabled or disabled, it applies only to new sessions .Existing sessions continue without any changes. To ensure that all connections follow the latest configuration, you must restart the firewall.

To restart the firewall, click the Restart Firewall button. Restarting the firewall terminates all active sessions and ensures that all new sessions operate according to the policy applied to the secure gateway. This action may temporarily affect network services and client connections.