Network Rules
Overview
Rules define behavior for incoming and outgoing traffic in the network, providing the functionality traditionally provided by firewalls, routers, and switches.
Rule Types
Firewall
(action = Accept / Drop / Reject)
Allows controlling the network's traffic by filtering both packets in and out - only allowing packets to pass through if matching established rules. These rules are typically related to securing the network.
NAT / PAT
(action = Translate)
Provides Network Address/Port Translation - commonly used to conserve external/internal IP addresses by translating public addresses through to private IP addresses. NAT/PAT also allows "hiding" true addresses of network computers, with the translation of external IP/port to internal address/port.
Static Routes
(action = Route)
Allows controlling traffic paths from the network. A common use would be to provide a default gateway which allows routing traffic out of a private network through an external network for Internet access.
Order of Rules
Rules are evaluated from top to bottom, and the order directly affects behavior. In some cases, changing the sequence can produce different outcomes. For example, a NAT or PAT rule that translates traffic to a new port may interact differently with a rule that blocks traffic by port, depending on which one is applied first. Because of this, rule ordering should be treated as a deliberate and important part of network design.
Modify Rule Order
Rule ordering is controlled by relative placement rather than direct repositioning. Instead of dragging a rule to a specific position, you select one or more rules and then choose which existing rule they should execute before. The system then reorders the selected rules accordingly.
- From the Top Menu, click Networks -> List
- Select the desired network
- From the left menu, click View
- From the left menu, click Rules
- Select the desired rule
- Determine the rule the desired rule should be moved above
- Click the 🡐 Move icon on the far right of the rule you wish to move
Pin a Rule
Pinning a rule will ensure the rule is always at the top or bottom of the ruleset.
- From the Top Menu, click Networks -> List
- Select the desired network
- From the left menu, click View
- From the left menu, click Rules
- Select the desired rule
- From the left menu, click Edit
- Select Pin
- Bottom - Pin the rule to the very bottom of the ruleset
- No (default) - Does not pin the rule
- Top - Pin the rule to the very top of the ruleset
- Click Submit
Rule Fields
Alias - Selects an Alias IP defined on the selected network
Any/None - Any source address; no filter on source addresses
Custom - Provides a text input field where a specific filter can be entered
- Individual IP Address - 192.168.1.200
- CIDR Network - 10.10.4.0/27
- IP Range - 192.168.1.50-192.168.1.55
Any specific IP address or network can be entered using the custom option; however, it's typically best to use one of the helper options to select a variable. Using a helper option rather than specifying static addresses allows the rule to continue working even when specific addresses are modified and allows for efficient cloning and recipe templates that include these network rules.
My Current IP Address - The source IP address that is accessing the UI
My DMZ IP - The DMZ (external-facing) IP assigned to the selected network
My IP Addresses - Helper option to select an IP address defined on the selected network
My Network Address - Helper option to use the selected network (entire subnet)
My Router IP - Helper option to use the selected network's router IP (default gateway)
Network Block - The full IP block assigned to the selected network
Other IP Address - Helper option to select a different network and use one of that network's individual IP addresses
Other Network Address - Helper option to select a different network and use that networks (entire subnet)
Other Network Block - The full IP block assigned to a different network
Other Network DMZ IP - The DMZ (external-facing) IP assigned to another network
Other Router IP - Helper option to select a different network and use that network's router IP (default gateway)
Only applicable for TCP / UDP protocols
Source or Destination Ports/Ranges - Multiple options can be combined with commas
- Individual Port - 80
- Multiple Ports - 80,443
- Port Range - 1000-1005
Network Rules
Create New Rule
- From the Top Menu, click Networks -> List
- Select the desired network
- From the left menu, click View
- From the left menu, click Rules
- From the left menu, click New
- Enter a Name for the rule
- (Optional), enter a Description
- Select Action
- Accept - allows packets that meet the rule criteria
- Drop - deny packets that meet the rule criteria
- Reject - deny specified packets and send ICMP destination unreachable back to the source, when permitted
- Route - routes/forwards packets that meet the rule criteria
- Translate - maps an address/port outside the selected network with an address/port within the selected network
- Select Protocol
- Select Direction
- Incoming - packets coming into the firewall
- Outgoing - packets going out of the firewall
- Select Interface (typically Auto)
- (Optional), Pin the rule to the top or bottom of the ruleset
- Configure any additional options, if desired
- Enable Throttle - set a traffic rate limit
- Track Rule Statistics - allows viewing total number of packets processed
- Trace/Debug Rule - enables tracing packets for diagnostic purposes
- Select Source
- See Rule Fields for descriptions of each field option
- Select Destination
- See Rule Fields for descriptions of each field option
- Select Target (route and translate actions only), directs where to send the traffic
- See Rule Fields for descriptions of each field option
- Click Submit
⚠️ Click Apply Rules to apply the changes.
Copy Rule (Clone)
- From the Top Menu, click Networks -> List
- Select the desired network
- From the left menu, click View
- From the left menu, click Rules
- Select the desired rule
- Click the 📋 Copy icon on the far right of the selected line
- Enter a Name for the rule
- Modify desired fields
- Click Submit
⚠️ Click Apply Rules to apply the changes.
View Existing Rules
- From the Top Menu, click Networks -> List
- Select the desired network
- From the left menu, click View
- From the left menu, click Rules
Modify Existing Rule
- From the Top Menu, click Networks -> List
- Select the desired network
- From the left menu, click View
- From the left menu, click Rules
- Select the desired rule
- From the left menu, click Edit
- Modify desired settings
- Click Submit
⚠️ Click Apply Rules to apply the changes.