313
14.2.2-F
SX-GATE >
…
This tab addresses connections initiated by SX-GATE itself.
Besides system functions like storing backups on some server,
outgoing connections includes those established by SX-GATE's
proxies.
Restricting SX-GATE's outgoing connections makes sense if for example SX-GATE
separates two networks which must not have access to each other. Direct connections
between the two networks can be prevented by an appropriate configuration of
forwarding rules. However if access to the proxy servers of SX-GATE is allowed, these
could be abused to get indirect access to the other network. With this control you can
restrict these outgoing connections.
Output rules: Source SX-GATE, destination
…
A new entry is created by filling out the input fields and clicking on "Add". Select an
existing entry and click "Copy" to use it as a template. You can edit entries by clicking
on the underlined items. With "Remove" you can discard the currently selected line.
The "Up" and "Down" buttons help you to group related entries.
Rules are evaluated in the given order. The first match applies.
Hence more specific rules have to be moved above more
general rules. So e.g. a rule for a certain individual IP address
must be moved above a rule which refers to the same protocol
but an arbitrary IP address.
The following inputs are available:
Active
Use this control to enable or disable a rule at any time. Select date and time to
configure a temporary firewall rule which is active until that point of time has been
reached.
Log
You can enable logging with this switch. For TCP connections only the initial
packet will be written to the log. For all other IP protocols every packet is logged.
You should enable logging only for diagnostic purposes or
for rules which are not used frequently. Otherwise your log
files may grow rapidly.