292
Controlling traffic at the security gateway
Using packet filters to allow or deny traffic
To create packet filter groups
1
In the SGMI, in the left pane, under Policy, click
Firewall
.
2
In the right pane, on the Packet Filters tab, click
New > Filter Group
.
3
In the Filter Group Properties dialog box, do the following:
4
On the Filter Sequence tab, select the filters you want to put in the filter group in the Available
filters list and click the right-arrow >> button to move them to the Selected filters list.
5
To rearrange the order of the filters in the sequence, select a filter in the Included filters list and
click
Up
or
Down
.
6
Optionally, on the Description tab, type a more detailed description than you typed in the Caption
text box.
7
Click
OK
.
8
Optionally, do one of the following:
■
To save your configuration now and activate later, on the toolbar, click
Save
.
■
To activate your configuration now, on the toolbar, click
Activate
.
When prompted to save your changes, click
Yes
.
9
You can use the packet filter group in the following ways:
■
To define a forward filter
■
In a VPN policy, to restrict the services available through a VPN tunnel
■
On a network interface, to restrict the types of packets passing into or out of the security
gateway
Related information
For further information related to this topic, see the following:
■
“Packet Filter Group Properties—General tab”
■
“Packet Filter Group Properties—Filter Sequence tab”
■
“Using packet filters as forwarding filters”
■
“Applying packet filters to a VPN tunnel”
■
“Applying packet filters to individual network interfaces”
Applying filters and filter groups
Filters and filter groups only affect traffic when you apply them to VPN tunnels and network
interfaces. When applied, they can restrict the services available, providing fine-grained control of
information distribution.
You can also apply a filter to all incoming and outgoing packets arriving on all network interfaces. This
use of a filter is referred to as a forwarding filter, meaning that it forwards all packets through the
security gateway, bypassing normal security checking.
You can activate filters in the following ways:
■
Applying packet filters to a VPN tunnel
■
Applying packet filters to individual network interfaces
■
Using packet filters as forwarding filters
Filter Name
Type a name for the filter group.
Caption
Type a brief description of the filter group.
Summary of Contents for Security 5600 Series, Security 5400 Series,Clientless VPN 4400 Series
Page 76: ...76 Managing administrative access Enabling SSH for command line access to the appliance...
Page 242: ...242 Defining your security environment Controlling full application inspection of traffic...
Page 243: ...243 Defining your security environment Controlling full application inspection of traffic...
Page 269: ...268 Limiting user access Authenticating using Out Of Band Authentication OOBA...
Page 373: ...372 Preventing attacks Enabling protection for logical network interfaces...
Page 509: ...508 Generating reports Upgrade reports...
Page 553: ...552 Advanced system settings Configuring advanced options...
Page 557: ...556 SSL server certificate management Installing a signed certificate...
Page 861: ...860 Index...