12.07.2015 Views

Symantec™ Security Gateways Reference Guide - Sawmill

Symantec™ Security Gateways Reference Guide - Sawmill

Symantec™ Security Gateways Reference Guide - Sawmill

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

86 Controlling user accessTime PeriodsTACACS+ authenticationTo use this authentication method, users must have installed the RSA SecurID software on a separatesystem behind the security gateway. The security gateway then sends and receives RSA SecurIDauthentication requests to that system for validation. For more information on RSA SecurID, see their Webpage at www.rsa.com.Configuration information for RSA SecurID authentication is found in your product’s administrator’sguide.TACACS+ is a TCP-based authentication method. The administrator must provide the IP address of theTACACS+ server to use TACACS+ authentication. In addition, the administrator must enable the daemon,and set up a template for the authentication method.Note: The configuration of the TACACS+ server is beyond the scope of this book.Time PeriodsTime range templateConfiguration information for TACAS+ authentication is found in your product’s administrator’s guide.Another method to control user access is the time periods feature. This feature lets the administrator limitthe time period that someone can gain access to the protected network. This time window usually mirrorswhen a company is open for business, or when the administrator is around to troubleshoot a problem.A time range template is a starting and ending time or date combination, such as July 1, 2003-July 31, 2003,Monday-Wednesday, or 4 PM-6 PM. Templates also support both days and times such as 4 PM-6 PM duringJuly 1, 2003-July 31, 2003 or 4 PM-6 PM during Monday-Wednesday.There are a number of time range templates already created. You have the ability to edit the templates torefine them to your unique requirements, or you can simply create new time range templates. The preconfiguredtime range templates include:EverydayWeekdaysWeekendWorkingHoursSunday through Saturday, 24 hours a day. This is also the time range used when no template is active.Monday through Friday, 24 hours a day.Saturday and Sunday, 24 hours a day.8:00 AM to 5:00 PM.Time range sequenceWhen creating a new rule, if no time period is selected, appears in the rule definition to signifythat the rule has no time restriction.A time range sequence is a group of time range templates joined together in an inclusive OR relationship.Each sequence is a group of time range templates combined in a uniquely named group. Once created, thesequence appears in the time range pull-down, and you can select it for a rule or notification.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!