Applicable Products
- QuWAN Orchestrator
- QuWAN vRouter
Details
The order in which firewall rules are evaluated on a vRouter deployed within a QuWAN segment determines which rule takes precedence. This priority depends on the source of the traffic the rule applies to.
LAN Source Traffic
Firewall Priority
- Custom rules: These are user-defined rules with the highest priority.
On your QuWAN device, you can manage custom firewall rules by navigating to the Firewall section. To create a new rule, click Add. To modify an existing rule, locate the rule in the list and click the edit icon under the Action column. - Device segment rules: These are pre-defined rules applied to all traffic within the device segment (where QuWAN vRouter resides).
To manage device segment settings, click QuWAN Device Settings page on your chosen QuWAN device and navigate to the dedicated Segment Settings section. - LAN segment rules: These are pre-defined rules specific to LAN traffic. LAN segment settings are configured within individual LAN port settings.
On your QuWAN device, access the QuWAN Device Settings page, locate the desired LAN port, click the edit icon under the Action column, choose the appropriate segment from the dropdown menu, and save the changes.
VPN Source Traffic
Firewall Priority
- Custom rules: Similar to LAN, custom rules have the highest priority.
- Device segment rules: These still apply to VPN traffic.
- QuWAN QBelt VPN user rules: These are pre-defined rules specifically for traffic originating from QuWAN QBelt VPN clients or users.
In QuWAN Orchestrator, assign segment access to QuWAN QBelt VPN users under VPN Server Settings > Privilege Settings. You can either define the segment during new user creation or edit existing users and choose the segment.
Further Reading
For details on segment and firewall configuration, see the QuWAN and QuWAN Orchestrator Web Help.
适用产品
- QuWAN Orchestrator
- QuWAN vRouter
详情
在QuWAN段内部署的vRouter上评估防火墙规则的顺序决定了哪个规则优先。这一优先级取决于规则适用的流量来源。
LAN源流量
防火墙优先级
- 自定义规则:这些是用户定义的最高优先级规则。
在您的QuWAN设备上,您可以通过导航到防火墙部分来管理自定义防火墙规则。要创建新规则,请点击添加。要修改现有规则,请在列表中找到该规则并点击操作列下的编辑图标。 - 设备段规则:这些是应用于设备段内所有流量的预定义规则(QuWAN vRouter所在位置)。
要管理设备段设置,请点击您选择的QuWAN设备上的QuWAN设备设置页面并导航到专用的段设置部分。 - LAN段规则:这些是特定于LAN流量的预定义规则。LAN段设置在各个LAN端口设置中配置。
在您的QuWAN设备上,访问QuWAN设备设置页面,找到所需的LAN端口,点击操作列下的编辑图标,从下拉菜单中选择适当的段并保存更改。
VPN源流量
防火墙优先级
- 自定义规则:与LAN类似,自定义规则具有最高优先级。
- 设备段规则:这些规则仍然适用于VPN流量。
- QuWAN QBelt VPN用户规则:这些是专门针对来自QuWAN QBelt VPN客户端或用户的流量的预定义规则。
在 QuWAN Orchestrator 中,在VPN服务器设置 > 权限设置下为QuWAN QBelt VPN用户分配段访问权限。您可以在创建新用户时定义段,或编辑现有用户并选择段。
进一步阅读
有关段和防火墙配置的详细信息,请参见 QuWAN和QuWAN Orchestrator Web帮助 。