FireBrick Port Guide
Port/Protocol groups
In many places, such as traffic shaping, filtering, routes, etc, you can set a range of ports and protocols to define the type of traffic being referenced. Some types of traffic use a number of different ports and protocols but you would want to allow all of these in one filter or use them all in one route. Port groups allow sets of protocol/port combinations to be defined as a named port group and used instead of specific ranges in filters, routes, etc.
| Name | Give the group a meaningful short name as this is what is shown in the list when groups can be used. |
| Security | This defines who can view or edit the group |
| Protocol | This allows the specific protocol to be specified, or Any. |
| Source ports | This allows a range of source ports to be specified. Applicable to TCP and UDP. Normally blank meaning any. |
| Target ports | This allows a range of target ports to be specifiied. Applicable to TCP and UDP. Typically just one port for the specific protocol, e.g. 80 for WWW |
| Add | Adds an entry to the group |
| Delete | Deletes the individual entry from the group |
| Erase | Erases the whole port group and all entries within it |
FireBrick Tunnel Traffic
A default port group in the factory reset config is FireBrick tunnel traffic which uses UDP port 1.
Technical Reference
- The security on a group does not affect whether a user can use the group.
- You can add a blank Any entry but this is pointless as the whole group becomes Any and you could simply not use a group instead.
- You cannot edit an entry, but you can add a new entry and then delete the old one.
- You cannot reorder entries as the order does not matter.
- The extra handling for ICMP types as applicable to filters does not apply within port groups
- If port ranges are specified with protocol Any then this means TCP or UDP as ports only apply to these