Adding Firewall Rules for Outgoing Activity by IP Address with the Rule Wizard

To add firewall rules to filter outgoing activity via the Rule Wizard, press the F6 key from the Plan Outgoing IP Security screen, shown in Analyzing Recent Data on Outgoing Activity by IP Address with the Rule Wizard (STRFW > 2 > 52).

The Add Firewall Outgoing IP Address screen appears:

                       ​  Add Firewall Outgoing IP Address​                         
                                                                                
 Type choices, press Enter.                                                    ​  
                                                                                
  ​
 IP Address  . . . . . .​   ​                                       
                                                                                
 Y=Yes, N=No, S=SSL only, A=Skip checks, B=SSL+Skip checks, L=Skip checks+Log,​   
 M=SSL+Skip checks+Log​                                                           
  ​
 FTP⁄REXEC . . . . . . .​   ​                                                     
                                                                                
                                                                                
                                                                                
                                                                                
                                                                                
                                                                                
                                                                                
                                                                                
                                                                                
                                                                                
                                                                                
                                                                                
 F3=Exit   F12=Cancel                               ​                             
                                                                                
                                                                                

Enter the IP address to which the new rule will apply in the IP Address field.

Enter a letter code in the FTP/REXEC field showing how Firewall is to react to requests for an outgoing connection via FTP/REXEC (including FTPLOG and REXLOG) to that IP address. The letters are:

  • Y: Accepted
  • N: Rejected
  • S: Only accepted over SSL connections
  • A: Accepted, without checking whether SQL statements are valid
  • B: Only accepted over SSL connections, without checking whether SQL statements are valid
  • L: Accepted, without either checking whether SQL statements are valid or logging the activity
  • M: Only accepted over SSL connections, without either checking whether SQL statements are valid or logging the activity.

If you do not enter a letter, requests to access it are handled according to the next highest generic rule that applies to it, up through the rule (if any) for *ALL.