18.07.2013 Views

Sidewinder G2 6.1.1 Administration Guide - Glossary of Technical ...

Sidewinder G2 6.1.1 Administration Guide - Glossary of Technical ...

Sidewinder G2 6.1.1 Administration Guide - Glossary of Technical ...

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Notes on selected proxy configurations<br />

8-26 Configuring Proxies<br />

To appropriately restrict access for the NetMeeting proxy rule, you<br />

can also configure network objects or other rule elements. For<br />

example, if you want to allow only administrators access to all<br />

NetMeeting features, you could create and specify a network object<br />

within rule that contains the IP addresses for all <strong>of</strong> your<br />

Administrators. See “Rule elements” on page 4-6 and “Creating proxy<br />

rules” on page 7-4 for more details.<br />

Generic TCP proxy considerations<br />

The following sections provide information on configuring the keep<br />

alive option for a generic TCP proxy, and restricting the outgoing port<br />

for a user-defined generic TCP proxy.<br />

Configuring the keep alive option for a generic TCP proxy<br />

The "keep alive" option allows you to configure the <strong>Sidewinder</strong> <strong>G2</strong> to<br />

actively ensure that a generic TCP proxy session is still active. When<br />

the keep alive option is turned on for a particular TCP proxy the<br />

<strong>Sidewinder</strong> <strong>G2</strong> will, at a determined time (the default is two hours),<br />

verify that the TCP session is still active. If the session is inactive, the<br />

<strong>Sidewinder</strong> <strong>G2</strong> will make a total <strong>of</strong> eight successive attempts to check<br />

for activity. If the session is still inactive, the <strong>Sidewinder</strong> <strong>G2</strong> will<br />

immediately terminate that session.<br />

To configure a generic TCP proxy to use the keep alive option, follow<br />

the steps below.<br />

1. Using a text editor, open the appropriate TCP proxy configuration file<br />

(/etc/sidewinder/proxy/proxyname.conf ).<br />

2. In the keep_alive field, toggle the value to [on].<br />

Note: Secure Computing strongly recommends setting the Idle Timeout value to<br />

zero (0) for any TCP proxy with the keep-alive option enabled. (The Idle Timeout value<br />

for a generic TCP proxy is configured in the Standard Application Defense.)<br />

3. Save the changes and exit the file.<br />

Note: You will need to restart the proxy for the changes to take effect.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!