18.07.2013 Views

Sidewinder G2 6.1.2 Administration Guide - Glossary of Technical ...

Sidewinder G2 6.1.2 Administration Guide - Glossary of Technical ...

Sidewinder G2 6.1.2 Administration Guide - Glossary of Technical ...

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Chapter 4: Understanding Policy Configuration<br />

Proxy rule basics<br />

– All—Allows connection service for both proxies and servers, but not<br />

service groups.<br />

– Proxy—Provides a connection through the <strong>Sidewinder</strong> <strong>G2</strong> in order to<br />

access a remote system.<br />

– Server—Provides a service (such as Telnet) directly on the <strong>Sidewinder</strong><br />

<strong>G2</strong>.<br />

– Service group—Allows multiple proxies and/or servers to be grouped<br />

together and used to define a single proxy rule.<br />

• type <strong>of</strong> network service requested—You can configure a proxy rule to allow<br />

or deny connections based on the type <strong>of</strong> network service that will be<br />

provided between the client and server. For proxy connections, the services<br />

include FTP, Telnet, and Web (HTTP), as well as many others.<br />

Optional criteria used to allow or deny a connection<br />

When setting up a proxy rule, you can also specify the following optional<br />

criteria for a connection.<br />

Note: You can specify any <strong>of</strong> the following criteria in an ‘allow” rule. However, only<br />

the authentication and date/time bullets apply to a ‘deny’ rule.<br />

• the user requesting the connection—You can configure a proxy rule to<br />

allow connections based on a group for which the user requesting the<br />

connection is a member. A user group is comprised <strong>of</strong> multiple users<br />

defined by the <strong>Sidewinder</strong> <strong>G2</strong> administrator. See “Users and user groups”<br />

on page 104 for more information on user groups.<br />

This option is only valid when using authentication or SSO.<br />

• authentication—You can configure a proxy rule to require the <strong>Sidewinder</strong><br />

<strong>G2</strong> to authenticate the user requesting the connection before granting the<br />

connection request. See “Supported authentication methods” on page 277<br />

for detailed information on the types <strong>of</strong> authentication services you can use.<br />

You can also configure a proxy rule to deny with authentication. The purpose<br />

<strong>of</strong> this type <strong>of</strong> rule would be to allow access to everyone except a specific<br />

group <strong>of</strong> users. For example, you might want to deny Telnet access to<br />

your contractors but allow access for your regular employees.<br />

Important: If you are not using SSO, configuring a deny with authentication<br />

proxy rule in a mixed service group (authenticating and non-authenticating<br />

services like Telnet and ping, respectively) will deny all non-authenticating<br />

services. However, if SSO authentication is configured, initial authentication will<br />

apply to all services contained in the service group. See “Service groups” on<br />

page 108 for more information.<br />

• the time and day when the connection request is made—You can<br />

configure a proxy rule to allow or deny connections based on the time, the<br />

day, or both.<br />

113

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!