System Settings
Whitelisting Client IP Addresses
As described above, a whitelist is a list of IP addresses or categories that will be allowed to pass,
regardless of whether they are identified as potentially malicious in the IRDB database. The
command format used to "block" addresses is similar to the format used to "pass" addresses
(explained above). The
pass
command permits inbound IP addresses found in the IRDB database
to access clusters defined on the ADC.
You can whitelist a single IP or a list of IPs. The list is comma separated. In the example below a
list of IP addresses is shown:
eqcli >
reputation whitelist 172.16.1.170,172.16.1.175,172.16.3.245
Verify your entry by entering:
eqcli >
show reputation whitelist
Allowed IP Name
Start IP Address
End IP Address
Allowed Direction
172.16.1.170
172.16.1.170
172.16.1.170
inbound
172.16.1.175
172.16.1.175
172.16.1.175
inbound
172.16.3.245
172.16.3.245
172.16.3.245
inbound
eqcli >
You could also enter a range of IP addresses to pass .If, for example, you enter
10.0.0.5 -
10.0.0.11
, all of the addresses from 10.0.0.5 to 10.0.0.11 will be passed. The following format is
used:
eqcli >
reputation pass
start IP
-
end IP
You can enter a range of ip addresses using CIDR notation. For example, you could enter the
following:
eqcli >
reputation pass 192.168.100.0/22
260
Copyright © 2014 Coyote Point Systems, A Subsidiary of Fortinet, Inc.
Summary of Contents for Equalizer GX Series
Page 18: ......
Page 32: ...Overview 32 Copyright 2014 Coyote Point Systems A Subsidiary of Fortinet Inc ...
Page 42: ......
Page 52: ......
Page 64: ......
Page 72: ......
Page 76: ......
Page 228: ......
Page 238: ......
Page 476: ......
Page 492: ......
Page 530: ......
Page 614: ......
Page 626: ......
Page 638: ......
Page 678: ......
Page 732: ...Using SNMP Traps 732 Copyright 2014 Coyote Point Systems A Subsidiary of Fortinet Inc ...
Page 754: ......
Page 790: ......
Page 804: ......
Page 842: ......
Page 866: ......