Select whether traffic enters the security
chain from one firewall interface and exits the security to the
other firewall interface, or if traffic can enter and exit the security
chain from both firewall interfaces. Unidirectional—The firewall
forwards all traffic to the security chain through Interface
#1 and receives the traffic back from the security chain
on Interface #2.
Both interfaces
must be in the same zone.
Bidirectional —The firewall forwards
client-to-server traffic to the security chain through Interface
#1 and receives the traffic back from the security chain
on Interface #2. The firewall forwards
server-to-client traffic to the security chain through Interface
#2 and receives the traffic back from the security chain
on Interface #1.
The flow
direction you select depends on the type of appliances in the security
chain. For example, if a security chain has stateless devices that
can examine both sides of a session, you could choose a unidirectional
flow. |