18.07.2013 Views

Sidewinder G2 6.1.2 Administration Guide - Glossary of Technical ...

Sidewinder G2 6.1.2 Administration Guide - Glossary of Technical ...

Sidewinder G2 6.1.2 Administration Guide - Glossary of Technical ...

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Chapter 4: Understanding Policy Configuration<br />

Proxy rule basics<br />

Suppose you want to allow all groups access to external FTP sites but only the<br />

engineering group access to FTP host 192.55.12.3. Table 15 shows the proxy<br />

rules in the order that they should be added to the rule group.<br />

Table 15: Proxy rules for sample configuration shown in Figure 49<br />

Proxy rule<br />

Criteria<br />

Rule 1:<br />

allow_eng_ftp<br />

Rule 2:<br />

deny_other_ftp<br />

Service Type Proxy Proxy Proxy<br />

Service FTP FTP FTP<br />

Action Allow Deny Allow<br />

Rule 3:<br />

allow_oth_ftp<br />

Source Burb Internal Internal Internal<br />

Source eng_net_group any (leave blank) any (leave blank)<br />

Destination Burb Internet Internet Internet<br />

Destination 192.55.12.3 192.55.12.3 any (leave blank)<br />

User Group any (leave blank) any (leave blank) any (leave blank)<br />

Authentication SafeWord<br />

Times/Days Fri 7am-7pm<br />

Application<br />

Defense (FTP)<br />

Allow Put/Get deny_all Allow Put/Get<br />

The following list summarizes key points to consider for the proxy rules listed in<br />

Table 15.<br />

• Rule 1 allows all systems in the engineering group authenticated FTP<br />

access to IP address 192.55.12.3 on the Internet, but only on Friday<br />

between 7:00 a.m. and 7:00 p.m.<br />

• This rule requires users to authenticate themselves via SafeWord before an<br />

FTP connection is allowed.<br />

• Rule 2 denies all systems in the trusted burb named internal from FTP<br />

service to IP address 192.55.12.3 on the Internet.<br />

• Rule 3 allows FTP service from all systems in the internal trusted burb to<br />

any external system in the Internet burb.<br />

117

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!