166
Defining your security environment
Defining traffic endpoints with network entities
■
■
■
“Authenticating tunnels using Entrust certificates”
Creating a network entity group for rules that apply to multiple entities
A network entity group is a collection of other network entities, such as hosts, domains, and subnets.
You can use network entity groups as the source or destination of traffic in a rule. By creating network
entity groups, you can reduce the number of rules you have to create. When multiple hosts require
similar rules, you can create one rule and apply it to the group instead of creating separate rules for
each network entity. For instance, a host entity (single computer) and a subnet entity (several
computers) could be combined into a group entity. Only one rule would then be needed to grant access
to both the host and the subnet.
You can use network entity groups to specify the source and destination of traffic controlled by packet
filters and address transforms. You can also use a network entity group as the local or remote endpoint
in VPN tunnels.
You must create the network entities that you want to include in the network entity group before you
create the network entity group.
Prerequisites
None.
To create a network entity group for rules that apply to multiple entities
1
In the SGMI, in the left pane, under Assets, click
Network
.
2
In the right pane, on the Network Entities tab, click
New > Network Entity Group
.
3
In the Network Entity Group Properties dialog box, on the General tab, do the following:
4
On the Network Entity tab, in the Available list, select the network entities that you want to include
in the group.
To move the selected network entities to the Selected list, click the right-arrow >> button. This
adds the network entities to the network entity group.
5
Optionally, on the Description tab, type a more detailed description than you typed in the Caption
text box.
6
Click
OK
.
7
Optionally, do one of the following:
■
To save your configuration now and activate later, on the toolbar, click
Save
.
■
To activate your configuration now, on the toolbar, click
Activate
.
When prompted to save your changes, click
Yes
.
8
Use the network entity group for any of the following:
■
To specify the source or destination of traffic in rules and packet filters.
■
To specify the local or remote endpoint in an IPsec static or gateway-to-gateway VPN tunnel.
■
To specify the local endpoint in a Client VPN tunnel.
■
To specify the source or destination of traffic in an address transform.
Entity name
Type a name for the network entity group.
Caption
Type a brief description of the network entity group.
Summary of Contents for Security 5600 Series, Security 5400 Series,Clientless VPN 4400 Series
Page 76: ...76 Managing administrative access Enabling SSH for command line access to the appliance...
Page 242: ...242 Defining your security environment Controlling full application inspection of traffic...
Page 243: ...243 Defining your security environment Controlling full application inspection of traffic...
Page 269: ...268 Limiting user access Authenticating using Out Of Band Authentication OOBA...
Page 373: ...372 Preventing attacks Enabling protection for logical network interfaces...
Page 509: ...508 Generating reports Upgrade reports...
Page 553: ...552 Advanced system settings Configuring advanced options...
Page 557: ...556 SSL server certificate management Installing a signed certificate...
Page 861: ...860 Index...