223
Defining your security environment
Controlling full application inspection of traffic
To configure the security gateway to support time synchronization
1
In the SGMI, in the left pane, under Assets, click
Proxies
.
2
In the right pane, in the Proxies table, click
NTP
, and then click
Properties
.
3
In the Proxy Properties dialog box, on the General tab, to enable the NTP proxy, click
Enable
.
4
On the Servers tab, in the Server IP text box, type the IP address or DNS-qualified name of the time
server you would like the security gateway to contact.
5
Click
Add
.
6
Click
Run Auto Configure
.
7
Click
OK
.
Related information
For further information related to this topic, see the following:
■
“Proxy Properties: NTP—General tab”
■
Supporting UNIX services
The RCMD proxy implements three services commonly used by UNIX users. Each service listens on a
different port. These services are:
Configuring the security gateway to support UNIX commands
RCMD provides a greater level of security for the rsh, rlogin, and rexec protocols than is obtained by
using a GSP. Proxying these connections through RCMD, as opposed to a GSP, offers tighter port usage
control and facilitates interactive strong authentication, which would not otherwise be available.
Prerequisites
None.
Configure the security gateway to support UNIX commands
To configure the security gateway to support UNIX commands, you must do the following:
■
Ensure the RCMD proxy is enabled
■
Create an RCMD service group
■
Create an allow rule for RCMD traffic
To ensure that the RCMD proxy is enabled
1
In the SGMI, in the left pane, under Assets, click
Proxies
.
2
In the right pane, in the Proxies table, click
RCMD
, and then click
Properties
.
exec (rexec)
You would use the exec service in a service group when you want to permit a user to execute
commands on a UNIX machine on your network. The commands are executed from a remote
machine. The default port for this service is port 512.
login (rlogin)
The login service is used when you want to allow a user to remotely log into another UNIX
machine. Typically, the login information is based upon what is seen on the remote machine, not
the local machine. The default port for this service is port 513.
shell (rsh)
The shell service in a service group corresponds to the rsh command under UNIX. Most
commonly, rsh is used to open a remote shell to another UNIX machine, and to interact with that
machine. The default port for this service is port 514.
Summary of Contents for Security 5600 Series, Security 5400 Series,Clientless VPN 4400 Series
Page 76: ...76 Managing administrative access Enabling SSH for command line access to the appliance...
Page 242: ...242 Defining your security environment Controlling full application inspection of traffic...
Page 243: ...243 Defining your security environment Controlling full application inspection of traffic...
Page 269: ...268 Limiting user access Authenticating using Out Of Band Authentication OOBA...
Page 373: ...372 Preventing attacks Enabling protection for logical network interfaces...
Page 509: ...508 Generating reports Upgrade reports...
Page 553: ...552 Advanced system settings Configuring advanced options...
Page 557: ...556 SSL server certificate management Installing a signed certificate...
Page 861: ...860 Index...