This chapter describes the factory default settings for the primary features, and provides the lists of predefined service and address objects. It includes the following sections:
Prevent all inbound traffic and allow all outbound traffic
Maximum number of custom firewall rules
100
NAT
Dynamic PAT
Enable
Maximum number of Static NAT rules
64
Maximum number of Port Forwarding rules
64
Maximum number of Port Triggering rules
15
Maximum number of Advanced NAT rules
32
Content Filtering
Disable
MAC Address Filtering
Disable
Maximum number of MAC Address Filtering rules
100
IP - MAC Binding
Maximum number of IP - MAC Binding rules
100
Attack Protection
Block Ping WAN Interface
Enable
Stealth Mode
Enable
Block TCP Flood
Enable
Block UDP Flood
Enable
Block ICMP Notification
Enable
Block Fragmented Packets
Disable
Block Multicast Packets
Enable
SYN Flood Detect Rate
128 max/sec (0 to 65535)
Echo Storm
15 packets/sec (0 to 65535)
ICMP Flood
100 packets/sec (0 to 65535)
Session Limits
Maximum number of connections
60000 (1000 to 60000)
TCP timeout
1200 seconds (5 to 3600 seconds)
UDP timeout
180 seconds (5 to 3600 seconds)
Application Level Gateway (ALG)
SIP ALG
Enable
H.323 ALG
Enable
Reports
Feature
Setting
Bandwidth Usage Reports
Bandwidth Usage Report by IP Address
Disable
Bandwidth Usage Report by Internet Service
Disable
Website Visits Report
Disable
WAN Bandwidth Reports
Disable
Security Services Reports
Anti-Virus Report
Disable
Application Control Report
Disable
Email Security Report
Disable
IPS Report
Disable
Network Reputation Report
Enable
Web Security Report
Disable
Default Service Objects
The following table displays all predefined service objects on the security appliance.
Service Name
Protocol
Port Start
Port End
Description
AIM-CONNECT
TCP
4443
4443
AOL Instant Messenger, direct connect
AIM-CHAT
TCP
5190
5190
AOL Instant Messenger, file transfer and chat
BGP
TCP
179
179
Border Gateway Protocol
BOOTP_client
UDP
68
68
Bootstrap Protocol
BOOTP_server
UDP
67
67
Bootstrap Protocol
CU-SEEME
TCP/UDP
7648
7652
Internet Videoconferencing Protocol
DHCP
UDP
67
67
Dynamic Host Configuration Protocol
DNS
TCP/UDP
53
53
Domain Name System
ESP
IP
Protocol 50
FINGER
TCP
79
79
Exchange of human-oriented status and user information
FTP-DATA
TCP
20
20
File Transfer Protocol, data transfer
FTP-CONTROL
TCP
21
21
File Transfer Protocol, control command
HTTP
TCP
80
80
HyperText Transfer Protocol
HTTPS
TCP
443
443
HTTP over SSL/TLS
ICMP Destination Unreachable
ICMP
3
0
ICMP Ping Reply
ICMP
0
0
ICMP Ping Request
ICMP
8
0
ICMP Redirect Message
ICMP
5
0
ICMP Router Advertisement
ICMP
9
0
ICMP Router Solicitation
ICMP
10
0
ICMP Source Quench
ICMP
4
0
ICMP Time Exceeded
ICMP
11
0
ICMP Timestamp
ICMP
13
0
ICMP Type-6
ICMP
6
0
Alternate Host Address
ICMP Type-7
ICMP
7
0
Reserved
ICQ
TCP
5190
5190
Instant Messenger
IDENT
TCP
113
113
Authentication Service/Identification Protocol
IKE
UDP
500
500
IPsec Key Exchange
IMAP
TCP
143
143
Internet Message Access Protocol
IMAP2
TCP
143
143
Internet Message Access Protocol Version 2
IMAP3
TCP
220
220
Internet Message Access Protocol Version 3
IPSEC-UDP-ENCAP
UDP
4500
4500
IPsec over UDP
IRC
TCP
6660
6660
Internet Relay Chat, de facto port: 6660 to 6669
ISAKMP
UDP
500
500
L2TP
UDP
1701
1701
Layer 2 Tunneling Protocol
NEWS
TCP
144
144
NFS
UDP
2049
2049
Network File System
NNTP
TCP
119
119
Network News Transfer Protocol, NNTP over SSL uses the port 563
POP3
TCP
110
110
Post Office Protocol Version 3
PPTP
TCP
1723
1723
Microsoft Point-to-Point Tunneling Protocol
RCMD
TCP
512
512
REAL-AUDIO
TCP
7070
7070
REXEC
TCP
512
512
Remote Process Execution
RIP
UDP
520
520
Routing Information Protocol
RLOGIN
TCP
513
513
RTELNET
TCP
107
107
Remote TELNET service
RTSP
TCP/UDP
554
554
Real Time Streaming Protocol
SFTP
TCP
115
115
Simple File Transfer Protocol
SHTTPD
TCP
8080
8080
Simple HTTPD
SHTTPDS
TCP
443
443
Simple HTTPD over SSL
SIP
TCP/UDP
5060
5060
Session Initiation Protocol
SMTP
TCP
25
25
Simple Mail Transfer Protocol
SNMP
TCP/UDP
161
161
Simple Network Management Protocol
SNMP-TRAPS
TCP/UDP
162
162
Simple Network Management Protocol - Trap
SQL-NET
TCP
1521
1521
SSH
TCP/UDP
22
22
Secure Shell Protocol
STRMWORKS
UDP
1558
1558
TACACS
TCP
49
49
Login Host Protocol
TELNET
TCP
23
23
TELNET Secondary
TCP
8023
8023
TELNET SSL
TCP
992
992
TFTP
UDP
69
69
Trivial FTP
VDOLIVE
TCP
7000
7000
VDOLive Protocol
Default Address Objects
The following table displays all predefined address objects on the security appliance. The IP address, IP address and netmask, or IP range for these objects will be automatically modified depending on your configuration or network connection.