12.07.2015 Views

Symantec™ Security Gateways Reference Guide - Sawmill

Symantec™ Security Gateways Reference Guide - Sawmill

Symantec™ Security Gateways Reference Guide - Sawmill

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Controlling service accessFilters69However, because a forwarding filter is basically an open window to the Internet with no security checksapplied to packets, setting up a GSP and writing a rule allowing this service to pass between the PPTPServer and the Universe gives you security over the connection that a forwarding filter does not.Note: Forwarding filters do not support network address translation (NAT). If a forwarding filter liesbetween an external client and an internal server, the internal server must have a routable address. Ifpossible, use a GSP rather than a forwarding filter. Using a GSP lets you NAT and log packets, whereforwarding filters do not.You can find the steps necessary to create a forwarding filter in your product’s administrator guide.VPN filterA VPN filter limits the types of permitted traffic allowed through a VPN tunnel. You can view a VPN filteras the opposite of a forwarding filter. A forwarding filter’s purpose is to increase the number of permittedservices through a secure entry point. By default, a VPN connection allows all services. When you apply aVPN filter to a VPN connection, the behavior of that connection is changed to restrict the types of servicespermitted.Filter groupsYou can couple filters to form groups (a collection of filters), letting you create more complex filters from aseries of simpler ones. Packets are checked against each filter in the filter group in sequence as shown inFigure 5-1. If a packet matches a filter group at any point, that action is immediately taken, and no furtherchecks performed. You should use deny filters only as part of a filter group because filters deny all trafficby default. A standalone deny filter disallows traffic that is not permitted in the first place.Figure 5-1Evaluating packets with filter groupsHow filters are usedYou can find the steps necessary to create a filter group in your product’s administrator guide.Filters are used in several ways:■■■At a security gateway interface to allow or deny packets that pass through that interface.As a property of a VPN tunnel to control the protocols that the tunnel supports. For example, a packetfilter could be designed that limits tunnel traffic to email (SMTP) only.As a property of all of the security gateway’s interfaces (a forwarding filter) that permits otherwiseunregulated traffic to pass through the system in cases where the proxies would not permit.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!