04.03.2013 Views

OfficeScan 10.6 Administrator's Guide - Trend Micro™ Online Help

OfficeScan 10.6 Administrator's Guide - Trend Micro™ Online Help

OfficeScan 10.6 Administrator's Guide - Trend Micro™ Online Help

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

<strong>Trend</strong> Micro <strong>OfficeScan</strong> <strong>10.6</strong> Administrator’s <strong>Guide</strong><br />

Firewall Policies<br />

11-8<br />

Firewall policies allow you to block or allow certain types of network traffic not<br />

specified in a policy exception. A policy also defines which firewall features get enabled<br />

or disabled. Assign a policy to one or multiple firewall profiles.<br />

<strong>OfficeScan</strong> comes with a set of default policies, which you can modify or delete.<br />

With Active Directory integration and role-based administration, each user role,<br />

depending on the permission, can create, configure, or delete policies for specific<br />

domains.<br />

The default firewall policies are as follows:<br />

TABLE 11-1. Default Firewall Policies<br />

POLICY<br />

NAME<br />

SECURITY<br />

LEVEL<br />

CLIENT<br />

SETTINGS<br />

All access Low Enable<br />

firewall<br />

Cisco Trust<br />

Agent for<br />

Cisco NAC<br />

Communicati<br />

on Ports for<br />

<strong>Trend</strong> Micro<br />

Control<br />

Manager<br />

ScanMail for<br />

Microsoft<br />

Exchange<br />

console<br />

Low Enable<br />

firewall<br />

Low Enable<br />

firewall<br />

Low Enable<br />

firewall<br />

EXCEPTIONS<br />

RECOMMENDED<br />

USE<br />

None Use to allow<br />

clients<br />

unrestricted<br />

access to the<br />

network<br />

Allow incoming<br />

and outgoing<br />

UDP traffic<br />

through port<br />

21862<br />

Allow all<br />

incoming and<br />

outgoing<br />

TCP/UDP traffic<br />

through ports 80<br />

and 10319<br />

Allow all<br />

incoming and<br />

outgoing TCP<br />

traffic through<br />

port 16372<br />

Use when<br />

clients have a<br />

Cisco Trust<br />

Agent (CTA)<br />

installation<br />

Use when<br />

clients have an<br />

MCP agent<br />

installation<br />

Use when<br />

clients need to<br />

access the<br />

ScanMail<br />

console

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!