198
Defining your security environment
Controlling full application inspection of traffic
Prerequisites
Complete the following task before beginning this procedure.
■
“Configuring access for CIFS and NBDGRAM traffic”
To enable mail slots filtering
1
In the SGMI, in the left pane, under Assets, click
Proxies
.
2
In the right pane, on the Proxies tab, click the NBDGRAM proxy and then click
Properties
.
3
In the Proxy Properties dialog box, on the Mailslots tab, check
Enable mail slots filtering
.
4
Click
OK
.
5
Optionally, do one of the following:
■
To save your configuration now and activate later, on the toolbar, click
Save
.
■
To activate your configuration now, on the toolbar, click
Activate
.
When prompted to save your changes, click
Yes
.
Related information
For related information, see the following:
■
“Proxy Properties: NBDGRAM—Mailslots tab”
Sending and receiving files
The File Transfer Protocol (FTP) is a TCP-based connection-oriented (the communications session is
established between the client and the server before data is transmitted) protocol that lets clients log
onto a remote FTP server to transfer or manage files. FTP is commonly used to transfer files from one
location to another through a pair of connections between a client and a server. FTP also lets you
remotely manage directories for those servers.
How the security gateway handles sending and receiving files
The security gateway uses the FTP proxy to support FTP connections. You can configure the FTP proxy
to limit connections to allow both PUT and GET commands (default), PUT commands only, or GET
commands only. You can also configure the FTP proxy to block connections based on length of user
names and passwords. This feature provides protection against user name/password buffer overflow
attacks.
By default, the FTP proxy protects against bounce attacks. The FTP proxy logs and disconnects the
control and data connections from an offending client if the client tries to send a PORT command for
an address that does not match the client's address.
You can also change the default logon banner, Secure Gateway FTP Server, to minimize the risk of
identifying the security gateway’s presence.
Configuring the security gateway to send and receive files
Prior to configuring FTP access, you should determine what level of access is to be granted, and who
should have that access. Additionally, you should check the directory level at which users will log on,
and ensure that this is correct, as granting FTP access gives users the ability to transfer files to and
from your FTP server.
Prerequisites
None.
Summary of Contents for Security 5600 Series, Security 5400 Series,Clientless VPN 4400 Series
Page 76: ...76 Managing administrative access Enabling SSH for command line access to the appliance...
Page 242: ...242 Defining your security environment Controlling full application inspection of traffic...
Page 243: ...243 Defining your security environment Controlling full application inspection of traffic...
Page 269: ...268 Limiting user access Authenticating using Out Of Band Authentication OOBA...
Page 373: ...372 Preventing attacks Enabling protection for logical network interfaces...
Page 509: ...508 Generating reports Upgrade reports...
Page 553: ...552 Advanced system settings Configuring advanced options...
Page 557: ...556 SSL server certificate management Installing a signed certificate...
Page 861: ...860 Index...