Management rules are applied only to management interfaces. The first step in the management rules is to follow the MGMTPROTECT rules, which can be divided into the following categories:
-
TCP flood restrictions
-
SSH rules
-
HTTPS rules
-
DNS rules
-
Syslog rules
-
OpenVPN rules
Management rules
-
Follow MGMTPROTECT rules.
-
Accept all packets in RELATED or ESTABLISHED state.
-
Accept all packets on TCP port 222.
-
Accept all packets on TCP port 443.
-
Accept all packets on TCP port 53.
-
Accept all packets on UDP port 53.
-
Accept all packets on TCP port 514.
-
Accept all packets on UDP port 514.
-
Accept all packets on UDP port 123.
-
Drop all other packets.