281
Controlling traffic at the security gateway
Understanding and using rules
You can use the Universe entity to write a rule that applies to anything. This procedure describes how
to create a rule that allows a host to Telnet or FTP to any system, anywhere.
Note:
Generally, you should not establish Universe-to-Universe rules because they impose no
restrictions on the source and destination of traffic through the security gateway.
Prerequisites
None.
To use the Universe entity to allow a host to Telnet or FTP to any system, anywhere
1
In the SGMI, in the left pane, under Policy, click
Firewall
.
2
In the right pane, on the Rules tab, click
New
.
3
In the Rule Properties dialog box, on the General tab, do the following:
4
Click
OK
.
5
Optionally, do one of the following:
■
To save your configuration now and activate later, on the toolbar, click
Save
.
■
To activate your configuration now, on the toolbar, click
Activate
.
When prompted to save your changes, click
Yes
.
Related information
For further information related to this topic, see the following:
■
Granting internal users access to public services
You may want to give internal users access to a public service, such as a news server, so they can
retrieve news articles.
Plan for the services that you want to allow, balancing allowed services with security. Your company’s
security policy should define acceptable services for the work environment. Access to the Web or a
mail server may be critical to the daily operation of the company, whereas access to a public game
server may not.
Enable
To enable the new rule, check
Enable
.
Rule name
Type a unique name for the rule.
Caption
Type a brief description of the rule.
Action
In this drop-down list, click
Allow
.
Arriving through
Select the security gateway interface through which the Telnet and FTP traffic will
enter the security gateway.
Source
Select the host network entity that you want to allow to Telnet and FTP.
Destination
Select
Universe
.
Leaving through
Select the security gateway interface through which the Telnet and FTP traffic will
leave the security gateway.
Service group
Select or create a service group that contains the Telnet and FTP protocols.
Time range
Optionally, from the drop-down list, select a time range.
Summary of Contents for Security 5600 Series, Security 5400 Series,Clientless VPN 4400 Series
Page 76: ...76 Managing administrative access Enabling SSH for command line access to the appliance...
Page 242: ...242 Defining your security environment Controlling full application inspection of traffic...
Page 243: ...243 Defining your security environment Controlling full application inspection of traffic...
Page 269: ...268 Limiting user access Authenticating using Out Of Band Authentication OOBA...
Page 373: ...372 Preventing attacks Enabling protection for logical network interfaces...
Page 509: ...508 Generating reports Upgrade reports...
Page 553: ...552 Advanced system settings Configuring advanced options...
Page 557: ...556 SSL server certificate management Installing a signed certificate...
Page 861: ...860 Index...