> For the complete documentation index, see [llms.txt](https://docs.eseye.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.eseye.com/hera604/configure/basic-settings/security.md).

# Security

Open **Basic Settings > Security > Firewall** to control traffic entering, leaving, or passing through the Hera 604.

<figure><img src="https://333373795-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FBMckwRPzYNvOiZyh1fl3%2Fuploads%2FDbqoROFf5SGYcDDBvSvk%2FScreenshot%202026-08-14%20at%2015.37.52.png?alt=media&amp;token=8a96ef0c-9abc-4c1a-86ec-df83a6b5621a" alt=""><figcaption></figcaption></figure>

> **Warning:** Disabling the firewall or creating an unrestricted inbound rule can expose the router and connected equipment. Make firewall changes only from an approved network design and keep access limited to the required sources, protocols, and ports.

Use the **Firewall** control to enable or disable firewall processing. Keep it enabled for operational deployments unless the security design explicitly requires otherwise.

#### Inbound rules

Inbound rules control traffic arriving at the router or its exposed services.

| Field                              | Description                                                                         |
| ---------------------------------- | ----------------------------------------------------------------------------------- |
| Rule name                          | Descriptive name for the rule.                                                      |
| Protocol                           | Protocol to which the rule applies, such as TCP, UDP, or ICMP.                      |
| Source IP address and netmask      | Limits the rule to a source host or network.                                        |
| Source port start and end          | Limits the rule to a source port or range. Enter the same value twice for one port. |
| Destination IP address and netmask | Limits the rule to a destination host, interface address, or network.               |
| Destination port start and end     | Destination service port or range. Enter the same value twice for one port.         |
| Permission                         | Allows or denies matching traffic.                                                  |
| Status                             | Enables or disables the individual rule.                                            |

The default configuration can include rules for SSH, HTTPS, ICMP, and CWMP. Do not remove or broaden these rules unless the change has been approved.

#### Outbound rules

Outbound rules control traffic sent from LAN devices through the router.

They use the same rule name, protocol, source, destination, port, permission, and status fields as inbound rules. Use them to allow or block defined traffic from specific local devices or networks.

#### Redirections

Redirections forward traffic received on an external WAN port to a service on a LAN device.

| Field                       | Description                                                |
| --------------------------- | ---------------------------------------------------------- |
| Redirection name            | Descriptive name for the forwarding rule.                  |
| Destination IP              | LAN address of the device receiving the forwarded traffic. |
| Protocol                    | Protocol used by the forwarded service.                    |
| External port start and end | Port or range reached on the router's WAN address.         |
| Internal port start and end | Port or range used by the destination LAN service.         |

> **Important:** A redirection exposes a LAN service through a WAN interface. Limit the rule to the required protocol and ports, and confirm that the destination device is secured before enabling it.

Use **Create** to add a firewall rule or redirection, **Remove** to delete one, and **Promote** to move a rule higher in its table. Select **Save** after making changes.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.eseye.com/hera604/configure/basic-settings/security.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
