If no other firewall rule is entered, the local network is protected by the interaction of network address translation and stateful inspection: Only connections from the local network generate an entry in the NAT table, whereupon the device opens a communication port. Communication over this port is monitored by stateful inspection: Only packets belonging to this connection may be communicated over this port. Attempts to access the local network from outside are met with an implicit deny-all strategy.
Transferring firewall rules with scripts
Firewall rules can be easily and conveniently transferred via scripts across device and software versions. Explicit example scripts can be found in the R&S®NC Support Knowledge Base.