S W G U s e r G u i d e
Chapter 19: Performing Additional Configuration Tasks
112
7. If you are ready to distribute and implement the changes in your system devices, click
.
Configuring Default and Device-Specific Access Lists
The Access List feature enables you to limit access to an swg device. The following Access List
definitions provides three access limitation options:
•
Management
Access
List
— Used for specifying the IPs of administrators who can access
Management Console, SSH, and SNMP. For example, to block access to the Management Console for
certain administrators, specify only the relevant IP addresses of authorized administrators.
If Access Lists are enabled, that is, the User Access List checkbox is selected, at least one IP must be
specified in this list, preferably the IP of the machine accessing the Management Console. This will
ensure that access is not totally blocked to the Management appliances.
•
Users
Access
List
— Used for controlling which Scanning Servers end‐users can browse through.
You specify the IP ranges that are allowed to use the SWG Scanning Server. Users whose IPs are in
the allowed range can browse; other users are blocked.
•
Access
to
M86
SWG
system
ports
— Used for controlling which device IPs have access to the
SWG system.
It is recommended that you use the procedure to modify default settings, and later after you have
added devices, to configure settings for specific devices.
Â
To limit IP access by defining Access Lists
1. Select
Administration
Æ
S
ystem
Settings
Æ
M86
Devices
.
2. In the Device tree that is displayed in the left pane, do either of the following:
• To define or alter the default Access Lists, select
Devices
Æ
Default
Values
Æ
Device
General
Settings
Æ
Access
Lists
. Values you define here will apply to all new devices that
you create. You can then modify the values for specific devices, as described in the next bullet.
• To define different Access Lists, that is , to override default Scanning Server values defined in
the previous bullet for a particular device, select
<device_ip>
, and then in the main window,
click the
Access
List
tab. This is relevant only if you added additional devices. For instructions
on adding additional devices, see
Adding Devices and Device Groups
.
3. Click
Edit
.
4. Select the
Use
Access
List
checkbox.
5. In the appropriate area, depending on whether you are defining IP Access Lists for Management,
Users, and/or M86 SWG system ports, do the following:
a. Click the
icon.
b. Fill in the IP range
From
IP
and
To
IP
.
c. Repeat for each IP range.
6. Click
Save
.
7. If you are ready to distribute and implement the changes in your system devices, click
.