WEST NETWORKS  •  THE INFRASTRUCTURE EXPERTS (352) 316-7701  ·  SHOP PEPLINK →

InControl 2 Firewall

InControl firewall: outbound/inbound/internal and local-service rules, SaaS- and region-based policy, content/application blocking, pushed instantly to thousands of routers.

The InControl firewall is a robust platform with a lot of options, and because it is applied at InControl it pushes to every matching device in seconds.

InControl firewall rule set — outbound, inbound, internal, and local-service groups, by tag.
InControl firewall rule set — outbound, inbound, internal, and local-service groups, by tag.

Hit Manage firewall rules, then Create rule set, and choose all, some, or none of the devices by tag. The rule groups mirror the router:

  • Outbound — anything originating from a LAN, VPN, or SpeedFusion and going out a WAN.
  • Inbound — anything coming in from a WAN.
  • Internal — traffic between your LANs, VLANs, and SpeedFusion peers, plus IDS and DoS prevention.
  • Local-service — rules for the router’s own services: SpeedFusion handshake, SpeedFusion data, web-admin access, DNS server, and SNMP server. For example, only allow web-admin access from one specific IP, or only allow the VPN handshake to originate in the United States.
Content & application blocking — block apps (e.g. HBO), adware/malware, custom domains, with exemptions and URL logging.
Content & application blocking — block apps (e.g. HBO), adware/malware, custom domains, with exemptions and URL logging.

Beyond content blocking there is application blocking — block an app such as HBO, or categories like adware and malware. You can add custom domains to block, update the content lists automatically, exempt individual domains, exempt whole groups, exempt subnets, and enable URL logging so you can see exactly what is being blocked.

SaaS- and region-based firewall rules using grouped networks — e.g. block a whole region, or company-services to a blacklist.
SaaS- and region-based firewall rules using grouped networks — e.g. block a whole region, or company-services to a blacklist.

Inbound and outbound rules take a source and destination that can be an IP address, IP network, MAC address, grouped network, SaaS, or region. Using the grouped networks you defined — for example a company services list and a blacklist — you might deny traffic from company services to the blacklist on the outbound rule, then create the mirror inbound rule (from blacklist to company services) so both directions are covered, with logging enabled. You can also match a SaaS destination such as WebEx, or a whole region — block Russia, for instance.

Instant, fleet-wide enforcement

Because the rule is applied at InControl, updating a blacklist blocks the destination across hundreds or thousands of routers in seconds — whether you do it manually (“block this domain”) or autonomously via the API. Rules on firewalls, like outbound policies, are evaluated top-down.