18.07.2013 Views

Sidewinder G2 6.1.1 Administration Guide - Glossary of Technical ...

Sidewinder G2 6.1.1 Administration Guide - Glossary of Technical ...

Sidewinder G2 6.1.1 Administration Guide - Glossary of Technical ...

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Protected host licensing and the Host Enrollment List<br />

3-28 General System Tasks<br />

If the enrollment list becomes full, additional audits will occur each<br />

time a new IP address attempts to make a connection to the Internet.<br />

However, only the IP addresses contained in the enrollment list will<br />

be allowed. IP addresses not already listed in the enrollment list will<br />

be unable to make a connection to the Internet. A user attempting to<br />

make a connection using a browser will receive a standard policy<br />

denial message. If a user is attempting to make a connection using a<br />

non-browser application (for example, FTP) the connection will<br />

simply be blocked and they will not receive an error message.<br />

You can configure the licexceed alarm event to email the administrator<br />

when the enrollment list reaches the maximum number allowed, and<br />

IP addresses are denied access due to a protected host license<br />

violation. See Chapter 17 for details on configuring alarms.<br />

If you reach the host enrollment maximum and you want to allow<br />

access to additional hosts, you will need to modify the host<br />

enrollment list to remove hosts entries that no longer need to be<br />

listed, upgrade your license, or upgrade to a larger <strong>Sidewinder</strong> <strong>G2</strong><br />

appliance. See “Displaying and modifying the Host Enrollment List”<br />

on page 3-29 for information on managing the host enrollment list.<br />

How hosts are calculated<br />

In general, a host is defined as a workstation that is protected by the<br />

<strong>Sidewinder</strong> <strong>G2</strong> and uses the <strong>Sidewinder</strong> <strong>G2</strong> to connect to the Internet.<br />

Any host that contains a unique IP address and that initiates a<br />

connection from a non-Internet burb is counted as a new host.<br />

The manner in which remote hosts access the <strong>Sidewinder</strong> <strong>G2</strong> may<br />

affect the host count. For example:<br />

Remote hosts that use dynamic addressing rather than static<br />

addressing may have multiple IP addresses added to the Host<br />

Enrollment List.<br />

Hosts accessing the <strong>Sidewinder</strong> <strong>G2</strong> via a VPN will be added to the<br />

Host Enrollment List if the VPN uses proxies to move the traffic<br />

from a non-Internet burb to another burb. Figure 3-11 illustrates<br />

this idea.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!