·
Select OK to save the policy.
If you are using accept policies to restrict access, you must remove all general access policies, such as
the default policy, that could be matched by a connection that you do not want. For more information, see
and
Ordering policies in policy lists
.
Requiring authentication to connect to the Internet
To require authentication, you must add users to the firewall configuration, see
.
Then you can add policies to require users to enter a user name and password to access HTTP, FTP, or
Telnet services through the DFL-500.
You can require user authentication for:
·
Int to Ext and Ext to Int policies
·
To selected addresses on the Internet
·
Using HTTP, FTP, or Telnet services
·
According to a schedule
The following example procedure requiring users on the internal network to authenticate to access HTTP
servers on the Internet is similar to any procedure requiring authentication. In this example, the DFL-500 is
running in NAT/Route mode.
To require authentication:
·
Add user names and passwords to the firewall.
See
.
·
Go to
Firewall > Policy > Int to Ext
.
·
Select New to add a new policy.
You can also select Insert Policy Before
on a policy in the list to add the new policy above a specific
policy.
·
Configure the policy to match the type of connection for which to require authentication.
Set Service to HTTP.
Set Action to AUTH.
·
Select OK to save the policy.
You must add the policy requiring authentication above the default policy and above any matching accept
policies in the policy list. For more information, see
DFL-500 User Manual
52