18.07.2013 Views

Sidewinder G2 6.1.1 Administration Guide - Glossary of Technical ...

Sidewinder G2 6.1.1 Administration Guide - Glossary of Technical ...

Sidewinder G2 6.1.1 Administration Guide - Glossary of Technical ...

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Proxy rule basics<br />

Table 4-5 summarizes criteria for a proxy rule that permits any client<br />

in a trusted burb to connect to any Web server located in the Internet<br />

burb.<br />

Note: This criteria reflects only the basic settings needed to allow access.<br />

Table 4-5. Sample settings for a simple proxy rule<br />

Basic rule<br />

Criteria<br />

Service Type<br />

Setting<br />

There are a number <strong>of</strong> optional effects you can configure for each<br />

proxy rule. For example, by adding the entry options shown in Table<br />

4-6, you can specify which internal users are allowed Web access,<br />

specify a time interval when Web access is allowed, and require<br />

authentication.<br />

Table 4-6. Optional proxy rule options<br />

Comments<br />

Proxy S<strong>of</strong>tware service type: proxy, server, or service<br />

group.<br />

Service HTTP Type <strong>of</strong> service: Telnet, FTP, Web (HTTP), etc.<br />

Action Allow Specifies whether to allow or deny a service.<br />

Source Burb Internal Name <strong>of</strong> the source burb.<br />

Source any (leave blank) Name <strong>of</strong> the source network object.<br />

Dest. Burb Internet Name <strong>of</strong> the destination burb.<br />

Destination any (leave blank) Name <strong>of</strong> the destination network object.<br />

App. Defense Web Contains application-specific properties.<br />

Optional Rule<br />

Criteria<br />

Setting<br />

Comments<br />

User Group marketing Specify the name <strong>of</strong> a user group.<br />

Authentication Password Specify the authentication method(s). FTP<br />

and Telnet proxies and console logins can<br />

also specify Password, Radius, SafeWord,<br />

SecurID, or SNK.<br />

Times/Day Mon-Fri<br />

7am-7pm<br />

Specify the time restrictions for allowing or<br />

denying service.<br />

Important: If you are not using SSO, user groups can be used in an allow rule only if the<br />

specified service supports authentication (login, Telnet, FTP, Web, or secure shell [SSH]).<br />

Understanding Policy Configuration 4-21

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!