18.07.2013 Views

Sidewinder G2 6.1.2 Administration Guide - Glossary of Technical ...

Sidewinder G2 6.1.2 Administration Guide - Glossary of Technical ...

Sidewinder G2 6.1.2 Administration Guide - Glossary of Technical ...

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Figure 47: User Groups<br />

user group<br />

named<br />

“Accounting”<br />

user group<br />

named<br />

“Engineering”<br />

Chapter 4: Understanding Policy Configuration<br />

Rule elements<br />

Figure 47 shows five users divided into two user groups: “Accounting” and<br />

“Engineering.” Suppose you want to allow both user groups Telnet access to<br />

the Internet. Also suppose you want to authenticate the “Accounting” user<br />

group differently from the “Engineering” user group. In this example you create<br />

two nearly identical rules to allow Telnet access, one for each user group. The<br />

only difference in the rules for each user group would be the authentication<br />

method you specify for each group.<br />

Network objects<br />

A network object is an entity for which you configure the <strong>Sidewinder</strong> <strong>G2</strong> to<br />

allow or deny connections. A network object can be an IP address, a host, a<br />

domain, a netmap, a subnet, or netgroup. When you create rules, you must<br />

specify a network object as the source or destination <strong>of</strong> the connection. (You<br />

may also select the All option, which serves as a wildcard.) The following<br />

subsections provide an overview <strong>of</strong> how each network object is used.<br />

Domain objects<br />

internal<br />

network<br />

<strong>Sidewinder</strong> <strong>G2</strong><br />

A domain object specifies a domain name that is registered in the Domain<br />

Name System (DNS). A domain object matches any domain or host name<br />

within the specified domain; for example, somehost.example.com matches<br />

example.com. See “Configuring domain objects” on page 142 for more<br />

information.<br />

Domain network objects are not supported in IP Filter rules.<br />

Internet<br />

105

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!