194
Defining your security environment
Controlling full application inspection of traffic
■
The CIFS proxy does not support UDP port 138 (NetBIOS datagram service). This service is used by
some Microsoft applications, most notably NT Domain Controllers, to locate certain types of
servers. If you want to communicate with domain controllers through a security gateway, you
should use the NetBIOS datagram (NBDGRAM) proxy when creating your rule for this type of
access.
You may also have to enable client side transparency on the inside interface for the inside domain
controller and enable it on the outside interface for the outside domain controller.
Configuring access for CIFS and NBDGRAM traffic
Prior to configuring access for CIFS and NBDGRAM, you should gather a list of any specific network
hosts to which you want to grant access. You should also determine what level of access is to be
granted, and who should have that access. Insure that you have double-checked all configuration
information, as users granted access have direct access to modify network files and folders.
Prerequisites
None.
Configure access for CIFS and NBDGRAM traffic
To configure access for the CIFS and NBDGRAM protocols, you must do the following:
■
Ensure the CIFS and NBDGRAM proxies are enabled
■
Create a CIFS and NBDGRAM service group
■
Create an allow rule for CIFS and NBDGRAM
To ensure that the CIFS and NBDGRAM proxies are enabled
1
In the SGMI, in the left pane, under Assets, click
Proxies
.
2
In the right pane, in the Proxies table, click
CIFS
, and then click
Properties
.
3
In the Proxy Properties dialog box, on the General tab, to enable CIFS, click
Enable
.
4
In the Caption text box, type a brief description of the CIFS proxy.
5
Optionally, on the Description tab, type a more detailed description than you typed in the Caption
text box.
6
Click
OK
.
7
In the right pane, in the Proxies table, click
NBDGRAM
, and then click
Properties
.
8
In the Proxy Properties dialog box, on the General tab, to enable CIFS, click
Enable
.
9
In the Caption text box, type a brief description of the NBDGRAM proxy.
10
Optionally, on the Description tab, type a more detailed description than you typed in the Caption
text box.
11
Click
OK
.
To create a CIFS and NBDGRAM service group
1
In the SGMI, in the left pane, under Assets, click
Protocols
.
2
In the right pane, on the Service Groups tab, click
New
.
3
In the Service Group Properties dialog box, on the General tab, in the Service Group Name text box,
type a name for this service group.
4
In the Caption text box, type a brief description of the service group.
5
On the Protocols tab, click
Add
to display a list of available protocols to add to this service group.
6
In the Network Protocol list box, click
cifs
.
Summary of Contents for Security 5600 Series, Security 5400 Series,Clientless VPN 4400 Series
Page 76: ...76 Managing administrative access Enabling SSH for command line access to the appliance...
Page 242: ...242 Defining your security environment Controlling full application inspection of traffic...
Page 243: ...243 Defining your security environment Controlling full application inspection of traffic...
Page 269: ...268 Limiting user access Authenticating using Out Of Band Authentication OOBA...
Page 373: ...372 Preventing attacks Enabling protection for logical network interfaces...
Page 509: ...508 Generating reports Upgrade reports...
Page 553: ...552 Advanced system settings Configuring advanced options...
Page 557: ...556 SSL server certificate management Installing a signed certificate...
Page 861: ...860 Index...