P O L I C Y C O N F I G U R A T I O N
Configuring Policies
9-4
Security Appliance User Guide
Version 3R2
9
[NOTE]
Intrazone blocking is disabled by default. All communication
among hosts on a zone is allowed.
Figure 9-3: Intrazone Policy
C O N F I G U R I N G G L O B A L P O L I C I E S
Global policies are not assigned to a specific zone and either allow or
deny packets to all zones.
Use the
set zone
command and specify
global
as the zone to create a
global policy:
set policy global {src_addr} {dst_addr} {srvc} {permit |
deny | reject}
[NOTE]
You must configure the src_addr and dst_addr in the global
zone.
. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
C O N F I G U R I N G P O L I C I E S
This section describes how to create, modify and delete policies. This
section includes the following topics:
•
Creating Policies
•
Naming Policies