06.03.2015 Views

iPECS SBG-1000 User Manual

iPECS SBG-1000 User Manual

iPECS SBG-1000 User Manual

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

<strong>iPECS</strong> <strong>SBG</strong>-<strong>1000</strong> <strong>User</strong> <strong>Manual</strong> (DATA Features)<br />

• Log Packets Matched by This Rule Select this check box to log the first packet from a<br />

connection that was matched by this rule.<br />

Schedule By default, the rule will always be active. However, you can define time segments<br />

during which the rule may be active, by selecting ‘<strong>User</strong> Defined’ from the ‘Schedule’ drop-down<br />

menu. If more than one scheduler rule is defined, the ‘Schedule’ drop-down menu will allow you to<br />

choose between the available rules. To learn how to configure scheduler rules, refer to<br />

Section 6.9.3.<br />

The order of the rules’ appearance represents both the order in which they were defined and the<br />

sequence by which they will be applied. You may change this order after your rules are already<br />

defined (without having to delete and then re-add them), by using the action icon and<br />

action icon.<br />

Figure 5.39 Move Up and Move Down Action Icons<br />

5.2.8.2 Adding ALG Rules<br />

The ‘ALG Rule Sets’ section enables you to define address and port processing rules for certain<br />

application protocols (such as, FTP, TFTP, SIP, and others), which carry the IP address inside the<br />

application data. Most of these protocols will not work with the NAT, unless the NAT is aware of<br />

them and does the appropriate translation.<br />

The NAT is application independent, therefore a specific Application Level Gateway (ALG) is<br />

required to perform payload monitoring and needed alterations to allow the application’s traffic to<br />

pass through the firewall. The ‘Input’ and ‘Output’ subsections of the ‘ALG Rule Sets’ feature (see<br />

Figure 5.35) are designated to display ALG rules for inbound and outbound traffic respectively.<br />

Note that <strong>iPECS</strong> <strong>SBG</strong>-<strong>1000</strong> is automatically configured with ALG rules for several widespread<br />

protocols. You can edit a rule by clicking its respective action icon, or remove it by clicking the<br />

action icon.<br />

To create an ALG rule, either inbound or outbound, click the ‘New Entry’ link that corresponds to<br />

the rule type you would like to define. The ‘Add ALG Rule’ screen appears.<br />

57

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!