18.07.2013 Views

Sidewinder G2 6.1.2 Administration Guide - Glossary of Technical ...

Sidewinder G2 6.1.2 Administration Guide - Glossary of Technical ...

Sidewinder G2 6.1.2 Administration Guide - Glossary of Technical ...

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Chapter 4: Understanding Policy Configuration<br />

Policy configuration basics<br />

100<br />

Figure 46: Traffic passing through the active rule groups<br />

traffic<br />

1. Traffic enters<br />

the <strong>Sidewinder</strong> <strong>G2</strong><br />

and is processed<br />

by the active<br />

IP Filter rules.<br />

active IP Filter rules proxies<br />

Rule group A<br />

Rule<br />

Rule group B<br />

Rule group C<br />

Rule<br />

2. No match is found,<br />

so traffic is forwarded<br />

to the proxies.<br />

Proxy<br />

Proxy<br />

Proxy - enabled<br />

Proxy<br />

Proxy<br />

3. A match is found at<br />

Proxy C, so the traffic is<br />

forwarded to the active<br />

proxy rules.<br />

active proxy rules<br />

Rule group A<br />

Rule group B<br />

Rule group C<br />

Tip: Always place the deny_all rule at the end <strong>of</strong> the active proxy rules list. This<br />

rule denies any traffic that reaches it. Therefore, any rules that are listed after the<br />

deny_all rule will not process any traffic.<br />

An example <strong>of</strong> traffic being processed by the active rules<br />

The following scenario walks you through the basic process used by the<br />

<strong>Sidewinder</strong> <strong>G2</strong> to process an outbound Telnet connection request. For<br />

simplicity, this scenario assumes that the active rules table consists <strong>of</strong> the<br />

following items:<br />

• Some non-TCP/UDP IP Filter rules.<br />

• A rule called NetMeeting that allows users to use audio and video<br />

conferencing components for NetMeeting ® .<br />

• A rule group called <strong>Administration</strong>, which allows <strong>Sidewinder</strong> <strong>G2</strong><br />

administrators to access the <strong>Sidewinder</strong> <strong>G2</strong>.<br />

• A rule called Internet Services, which includes a service group that allows<br />

access to the most commonly used Internet services, including Telnet. (For<br />

information on service groups, see “Service groups” on page 108.)<br />

• All proxies included in those rules are enabled in the appropriate burbs.<br />

• A deny_all rule that will deny any requests that did not match any other<br />

rules. This rule acts as a safeguard against traffic that did not meet any rule<br />

criteria, and may or may not be desirable depending on your site’s security<br />

policy.<br />

Rule<br />

Rule<br />

4. A match is found in Rule<br />

Group B. The traffic is<br />

processed by the rule<br />

specifications.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!