30.01.2015 Views

Administrator's Guide - Kerio Software Archive

Administrator's Guide - Kerio Software Archive

Administrator's Guide - Kerio Software Archive

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

7.7 Partial Retirement of Protocol Inspector<br />

User not authenticated yet who attempts to open a Web site will be automatically redirected<br />

to the authentication page (or authenticated by NTLM, or logged in from the corresponding<br />

host). After a successful authentication, users specified in the NAT rule (see figure 7.35) will<br />

be allowed to access also other Internet services. As well as users not specified in the rules,<br />

unauthenticated users will be disallowed to access any Web site or/and other Internet services.<br />

Note: In this example, it is assumed that client hosts use the <strong>Kerio</strong> Control DNS Forwarder or<br />

local DNS server (traffic must be allowed for the DNS server). If client stations used a DNS<br />

server in the Internet (this configuration is not recommended!), it would be necessary to<br />

include the DNS service in the rule which allows unlimited Internet access.<br />

7.7 Partial Retirement of Protocol Inspector<br />

Under certain circumstances, appliance of a protocol inspector to a particular communication<br />

might be undesirable. To disable specific protocol inspection, define corresponding source<br />

and destination IP addresses and a traffic rule for this service that will define explicitly that<br />

no protocol inspector will be used.<br />

Example<br />

A banking application (client) communicates with the bank’s server through its proper<br />

protocol which uses TCP protocol at the port 2000. Supposing the banking application is<br />

run on a host with IP address 192.168.1.15 and it connects to the server server.bank.com.<br />

This port is used by the Cisco SCCP protocol. The protocol inspector of the SCCP would be<br />

applied to the traffic of the banking client under normal circumstances. However, this might<br />

affect functionality of the application or endanger its security.<br />

A special traffic rule, as follows, will be defined for all traffic of the banking application:<br />

1. In the Configuration → Definitions → Services section, define a service called Internet Banking:<br />

this service will use TCP protocol at the port 2000 and no protocol inspector is used<br />

by this communication.<br />

2. In the Configuration → Traffic Policy → Traffic Rules section, create a rule which will<br />

permit this service traffic between the local network and the bank’s server. Specify that<br />

no protocol inspector will be applied.<br />

107

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!