©2015 Cradlepoint. All Rights Reserved.
|
+1.855.813.3385
|
cradlepoint.com
71
User Manual
/
AER3100/AER3150
SECURITY
IDENTITIES
HOST ADDRESSES
Identities are reusable groups of items that are added to filter policy
rules. A match on any single item in the group will cause the rule
to match. Identities are referenced in rules by their name. Choosing
descriptive names like “NW Sales Team” or “Engineering” will aid in
understanding existing rules and in choosing identities for new rules.
A Host identity can contain IPv4, IPv6, and Fully Qualified Domain Name
addresses. A single identity can contain a combination of IPv4 and IPv6
addresses. IPv4/6 addresses cannot be combined with FQDN addresses
in the same identity.
IP addresses are entered using CIDR notation, e.g. 1.2.3.4/32 and
0123:4567::CDEF/128. FQDN addresses are entered with at least one dot
separating a top-level domain from a root zone, e.g. cradlepoint.com.
To add a Host Address Identity, click
Add
.
PORTS
A port identity member can be entered as a single Start port number or as a port range by entering both a
Start and End port number.
To add a Port Identity, click
Add
.
MAC ADDRESSES
MAC addresses are entered in the form aa:bb:cc:dd:ee:ff.
To add a MAC Address Identity, click
Add
.
REPUTATION
A reputation file contains a list of IPv4 and IPv6 addresses and networks with CIDR notation, one address
or network per line. Reputation identity allows you to upload a file from a reputation service provider (e.g.,
www.spamhaus.org/drop/
). It also provides a way to maintain large lists of IPs that need firewall attributes
applied to them. Files should be in the format where each line starts with an IP address or IP network and
prefix length. All other lines are rejected. Currently we support adding 65535 IPs per reputation identity.
To add a Reputation Identity, click
Add,
then select and upload your file.
APPLICATION SETS
An Application Set is a selection of possible application identifications that can be matched against in Zone
Firewall policies.
To add an Application Set Identity, click
Add
.