238
Defining your security environment
Controlling full application inspection of traffic
4
Optionally, on the Description tab, type a more detailed description than you typed in the Caption
text box.
5
Click
OK
.
6
Optionally, do one of the following:
■
To save your configuration now and activate later, on the toolbar, click
Save
.
■
To activate your configuration now, on the toolbar, click
Activate
.
When prompted to save your changes, click
Yes
.
Related information
For further information related to this topic, see the following:
■
“Proxy Properties: Telnet—General tab”
■
Allowing ICMP traffic
The ping utility is often used when troubleshooting network connectivity, letting you ping external
networks and receive a response back through the security gateway. However, to ping hosts that reside
on the opposite side of the security gateway, you have to tell the security gateway to allow this type of
traffic. This is normally done by enabling the ping proxy (pingd). The ping proxy examines all ICMP
traffic for correctness and adherence to RFC specifications.
How the security gateway handles ICMP traffic
By default, ICMP packets hitting the security gateway are dropped, as the security stance of an
unmodified security gateway is to appear invisible on the network. However, it is often advantageous
to have the security gateway respond to ICMP requests, especially when testing or troubleshooting.
The ping proxy provides a mechanism for the security gateway to respond to ICMP requests.
Note:
The security gateway does not pass the original ICMP packets the source generates and does not
include the original client data payload in the echo request to the real destination if the security
gateway is not the target of the ping.
Using the ping proxy, the security gateway constructs a new echo request with a new sequence
number, time-to-live (affecting traceroute), and new optional data so that other protocols cannot be
tunneled on top of the ICMP echo. If the security gateway receives an ICMP echo request through a
tunnel, and that tunnel is not forcing traffic through the proxies, the packets are permitted to pass
unmodified. If the security gateway is the target of the ICMP echo request, the ping proxy responds to
the client normally.
Destination
Select the defined network entity to which Telnet traffic is destined. This can be a host
network entity representing a specific machine or a subnet network entity representing
your internal network.
Leaving through
Select the connection point through which traffic leaves the security gateway.
Service group
Select the service group containing the telnet protocol.
Summary of Contents for Security 5600 Series, Security 5400 Series,Clientless VPN 4400 Series
Page 76: ...76 Managing administrative access Enabling SSH for command line access to the appliance...
Page 242: ...242 Defining your security environment Controlling full application inspection of traffic...
Page 243: ...243 Defining your security environment Controlling full application inspection of traffic...
Page 269: ...268 Limiting user access Authenticating using Out Of Band Authentication OOBA...
Page 373: ...372 Preventing attacks Enabling protection for logical network interfaces...
Page 509: ...508 Generating reports Upgrade reports...
Page 553: ...552 Advanced system settings Configuring advanced options...
Page 557: ...556 SSL server certificate management Installing a signed certificate...
Page 861: ...860 Index...