283
Controlling traffic at the security gateway
Understanding and using rules
Related information
For further information related to this topic, see the following:
■
Providing public access to a server on a service network
You can give the general public access to an internal server you operate. For example, if you have an
internal Web server that hosts your company’s Web site, you can make this service available to the
general public without compromising your security.
Prerequisites
None.
To provide public access to a server on a service network
1
Place the server on a service network.
This service network can be an internal network, but separated from the main network on which
your protected resources reside.
2
Determine the IP addressing scheme.
You may want the server to use a routable IP address. In addition, you may want to use a non-
routed address to hide its true destination.
If you choose to use a non-routable IP address for the server, in the SGMI, set up a service redirect,
and tell the general public to direct their service requests to the publicly known IP address.
3
To create a rule to allow public access to the server on a service network, in the left pane, under
Policy, click
Firewall
.
4
In the right pane, on the Rules tab, click
New
.
5
In the Rule Properties dialog box, on the General tab, do the following:
6
On the Antivirus tab, to enable scanning of SMTP, POP3, HTTP, or FTP files, check the desired
protocol, and then under each, select the antivirus features to be used.
7
On the Content Filtering tab, in the Content profile drop-down list, select a content profile.
Enable
To enable the new rule, check
Enable
.
Rule name
Type a unique name for the rule.
Caption
Type a brief description of the rule, identifying the internal server to which you are
providing access.
Action
In this drop-down list, click
Allow
.
Arriving through
Select
an outside interface.
Source
Select
Universe
.
Destination
Select the host network entity of the server to which you want to grant access.
Leaving through
Select an outside interface.
Service group
Select or create a service group that contains the protocol required to exchange
information with the internal server.
For example, to access an internal Web server, select the Web service group.
Time range
Optionally, select a time range during which the public can access the internal
server.
Summary of Contents for Security 5600 Series, Security 5400 Series,Clientless VPN 4400 Series
Page 76: ...76 Managing administrative access Enabling SSH for command line access to the appliance...
Page 242: ...242 Defining your security environment Controlling full application inspection of traffic...
Page 243: ...243 Defining your security environment Controlling full application inspection of traffic...
Page 269: ...268 Limiting user access Authenticating using Out Of Band Authentication OOBA...
Page 373: ...372 Preventing attacks Enabling protection for logical network interfaces...
Page 509: ...508 Generating reports Upgrade reports...
Page 553: ...552 Advanced system settings Configuring advanced options...
Page 557: ...556 SSL server certificate management Installing a signed certificate...
Page 861: ...860 Index...