18.07.2013 Views

Sidewinder G2 6.1.2 Administration Guide - Glossary of Technical ...

Sidewinder G2 6.1.2 Administration Guide - Glossary of Technical ...

Sidewinder G2 6.1.2 Administration Guide - Glossary of Technical ...

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Chapter 8: Creating Rules and Rule Groups<br />

Creating IP Filter rules<br />

232<br />

3 In the Source Burb drop-down list, select the burb through which the<br />

<strong>Sidewinder</strong> <strong>G2</strong> should route to get to the source IP address.<br />

4 In the Destination Burb drop-down list, select the burb through which the<br />

<strong>Sidewinder</strong> <strong>G2</strong> should route to get to the destination IP address.<br />

5 In the Source Show drop-down list, select the type <strong>of</strong> network object or<br />

group to use as the source object.<br />

6 In the displayed Source list, select the source object to use for this rule.<br />

7 In the Destination Show drop-down list, select the type <strong>of</strong> network object or<br />

group to use as the destination object.<br />

8 In the displayed Destination list, select the destination object to use for this<br />

rule.<br />

9 In the Source Port Range field, specify the port or range <strong>of</strong> ports (inclusive)<br />

in which connections are allowed to be made to or initiated from the<br />

corresponding address. Note the following:<br />

• Valid values are 1–65535.<br />

• To specify “any port,” leave the field blank.<br />

If configuring an ICMP or Other rule, port configuration is not an option.<br />

10 In the Destination Port Ranges field, do one <strong>of</strong> the following:<br />

• To specify “any port,” leave the field blank.<br />

• To specify one or more port or port ranges (inclusive) in which<br />

connections are allowed to be made to or initiated from the<br />

corresponding address, click New. Valid values are 1–65535. You also<br />

have the option to modify or delete existing entries.<br />

If configuring an ICMP or Other rule, port configuration is not an option.<br />

11 In the NAT Mode drop-down list, select one <strong>of</strong> the following options:<br />

• None—This option will disable NAT for this rule.<br />

• Normal—All packets that match this rule will be translated as follows:<br />

the source address will be translated to the associated NAT address,<br />

and the source port will be translated to a port within the NAT port<br />

range.<br />

• Source Port—All packets that match this rule will be translated as<br />

follows: the source address will be translated to the associated NAT<br />

address. The source port will not be translated.<br />

12 In the NAT Address drop-down list, select the object (IP address, host, or<br />

subnet) that will replace the original source address when it is translated.<br />

(To filter the type <strong>of</strong> objects that appear in the list, select an option from the<br />

Show drop-down list.)<br />

Important: If you selected Source Port NAT in the previous step, you must<br />

specify an alias IP address or a subnet that contains at least one alias IP<br />

address as the NAT Address. If you specify an interface IP address or subnet<br />

that does not contain an alias IP address, this rule will not pass traffic and audit<br />

will be generated.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!