135
Establishing your network
Allowing multicast traffic
3
In the Rule Properties dialog box, on the General tab, do the following:
4
Optionally, on the Description tab, type a more detailed description than you typed in the Caption
text box.
5
Click
OK
.
6
Optionally, do one of the following:
■
To save your configuration now and activate later, on the toolbar, click
Save
.
■
To activate your configuration now, on the toolbar, click
Activate
.
When prompted to save your changes, click
Yes
.
Related information
For further information related to this topic, see the following:
■
■
“How the security gateway handles DHCP traffic”
Allowing multicast traffic
Multicast is a bandwidth-conserving technology that reduces traffic by delivering a stream of
information to defined hosts only, as compared to broadcast traffic that is sent to every host on a
network segment. Multicast uses the concept of a group, which is defined as an arbitrary number of
receivers that have expressed an interest in receiving a particular data stream. Using a multicast
router, packets sent from a single source are reviewed, replicated, and then sent only to the members
in the multicast group. Systems not part of the multicast group do not receive unnecessary traffic.
Multicast packets can also traverse networks, assuming that the router between the two networks is
multicast enabled. This is another distinct advantage over using the broadcast address on a network,
as routers do not forward broadcast packets.
Enabling this option configures the security gateway to allow multicast traffic.
Note:
You cannot configure the security gateway to act like a multicast router and rebroadcast
multicast packets to protected hosts. Allowing multicast traffic only instructs the security gateway not
to filter and drop multicast packets it receives.
For more information about multicast support, see RFC 1112,
Host Extensions for Multicasting,
and
RFC 2236;
Internet Group Management Protocol, Version 2
.
Rule name
Type a name for this rule, such as Allow_multi_hop_DHCP.
Caption
Type a brief description of the rule.
Action
Click
allow
.
Arriving through
Select the interface closest to the DHCP server.
Source
Create a host network entity to represent the DHCP server.
Destination
Create a subnet entity to represent the next subnet to which you want to relay the
DHCP traffic.
Leaving through
Select the interface that connects to the subnet you specified as the destination.
Service group
Select the service group containing the UDP protocol for port 67.
Summary of Contents for Security 5600 Series, Security 5400 Series,Clientless VPN 4400 Series
Page 76: ...76 Managing administrative access Enabling SSH for command line access to the appliance...
Page 242: ...242 Defining your security environment Controlling full application inspection of traffic...
Page 243: ...243 Defining your security environment Controlling full application inspection of traffic...
Page 269: ...268 Limiting user access Authenticating using Out Of Band Authentication OOBA...
Page 373: ...372 Preventing attacks Enabling protection for logical network interfaces...
Page 509: ...508 Generating reports Upgrade reports...
Page 553: ...552 Advanced system settings Configuring advanced options...
Page 557: ...556 SSL server certificate management Installing a signed certificate...
Page 861: ...860 Index...