185
Defining your security environment
About service groups
10
Click
OK
.
11
Optionally, do one of the following:
■
To save your configuration now and activate later, on the toolbar, click
Save
.
■
To activate your configuration now, on the toolbar, click
Activate
.
When prompted to save your changes, click
Yes
.
12
After creating the service group, you can do the following:
■
To configure proxy settings for a protocol in the service group, on the Protocols tab, select the
protocol and click
Add
.
■
To control traffic using the protocols in the service group, add the service group to a rule.
Related information
For further information related to this topic, see the following:
■
“Service Group Properties—General tab”
■
“Service Group Properties—Protocols tab”
■
“Service Group Properties—Additional Parameters tab”
■
“Controlling full application inspection of traffic”
■
“Using service groups to customize protocols for rules”
■
Using service groups to customize protocols for rules
Service groups let you customize protocols for certain rules without changing protocol behavior for
other rules.
To do this, you create a service group specifically for a rule or set of rules. After you add protocols to
the service group, you can configure parameters of the protocols specifically for their use in that
service group.
lists protocols can be customized in a service group:
Table 6-5
Customizable protocols
Protocol
Configurable parameters
CIFS
File handling permissions such as read, write, and print.
“Parameters for cifs—General tab”
FTP
Enabling of FTP puts and gets, and the ability to include additional commands.
“Parameters for ftp—General tab”
HTTP
Enabling of uploads, HTTPS, DCOM over HTTP, FTP protocol conversion, and an external
Web proxy.
“Parameters for http—Options tab”
“Parameters for http—Web Proxy tab”
NNTP
News permissions such as newsreader, posting, filter policy and cancel messages.
“Parameters for nntp—General tab”
POP3
Enabling of POP3 extensions such as the CAPA command and AUTH commands.
“Parameters for pop-3—Advanced tab”
realaudio and
realaudio_proxy
Setting bandwidth limit.
Summary of Contents for Security 5600 Series, Security 5400 Series,Clientless VPN 4400 Series
Page 76: ...76 Managing administrative access Enabling SSH for command line access to the appliance...
Page 242: ...242 Defining your security environment Controlling full application inspection of traffic...
Page 243: ...243 Defining your security environment Controlling full application inspection of traffic...
Page 269: ...268 Limiting user access Authenticating using Out Of Band Authentication OOBA...
Page 373: ...372 Preventing attacks Enabling protection for logical network interfaces...
Page 509: ...508 Generating reports Upgrade reports...
Page 553: ...552 Advanced system settings Configuring advanced options...
Page 557: ...556 SSL server certificate management Installing a signed certificate...
Page 861: ...860 Index...