background image

Changing the Policy for an EFW NIC

11

f

Click in the Direction cell, and select 

Out 

from the drop-down list.

g

Click the check box in the Audit cell to enable audit. 

You now have an effective “Deny outbound TCP SYN” rule. This rule 
should directly follow the Windows Standard 2000 rule set you added 
in step 6. If it does not, highlight the Deny outbound TCP SYN rule 
row, and use the arrow buttons to position it directly after the 
Windows 2000 Standard rule set.

8

Click 

Save

 to save the new policy information.

For more information on creating policies, refer to the section “Creating 
Policies and Rules” in the 

3Com Embedded Firewall Administration Guide

.

Creating a Sample Device Set

Next you will create a sample device set that enforces the policy you created 
in the previous section. A device set is a collection of EFW devices that are 
associated with a specific policy. You can define any number of device sets and 
assign EFW devices to any one of those device sets.

To create the sample device set, follow the steps below.

1

From the 

Main

 menu, select 

New

 -> 

Device Set

. The New Device Set 

window appears.

2

Type 

Sample 

in the Device Set Name field. 

3

Select the 

No IP Initiation 

policy, which you created in the previous section, 

from the Policy for the New Device Set box. 

4

Click 

OK

. The device set information appears in the working frame.

5

Select a heartbeat interval of 

15 minutes

 from the Heartbeat drop-down 

list. (The heartbeat determines how often the EFW devices issue a 
heartbeat, or status update, to the Policy Server.) 

6

Type 

Sample device set enforcing the No IP Initiation policy

 in the 

Description field. This field is optional and exists solely to assist an 
administrator in identifying the contents of the device set.

7

Click 

Save

.

Содержание 3CR990

Страница 1: ...3Com Embedded Firewall Software for the 3CR990 Network Interface Card NIC Family Quick Start Guide http www 3com com http www 3com com registration frontpg pl 09 2110 000 Published December 2001...

Страница 2: ...ges in the product s and or the program s described in this documentation at any time If there is any software on removable media described in this documentation it is furnished under a license agreem...

Страница 3: ...ecovery diskette 5 Importing the No sniffing no spoofing pre defined Policy and Assigning it to the Default Device Set 6 Installing and Registering an EFW NIC 7 Verifying NIC Registration 8 Changing t...

Страница 4: ......

Страница 5: ...information for expanding your EFW system to best suit your security needs What You Will Need Before you install the EFW software you will need A computer to host the Policy Server and Management Cons...

Страница 6: ...w provide instructions for installing a Policy Server and Management Console on a single system using the Typical installation method 1 Insert the 3Com product CD in the appropriate drive the Installa...

Страница 7: ...s offered on this screen 2 Select Confirm Create New Domain 3 Enter a domain name in the Domain Name field The domain name is used only as a reference to assist you in identifying a particular domain...

Страница 8: ...w system are as follows Login admin Password admin 3 Select the Policy Server that you just created from the Policy Server list 4 Click Connect The Embedded Firewall Management Console window appears...

Страница 9: ...upon creation of a new EFW domain After installing your first policy server in an EFW domain it is critical to make a copy of the files named public key and server keystore from your installation Sav...

Страница 10: ...fing pre defined policy follow the steps below 1 From the Main menu select Import Policy Rule set The Import Policy Rule Set window appears 2 Select Policy and click Next 3 Click Browse and navigate t...

Страница 11: ...ry on the computer that will receive the EFW NIC installation on a computer on which a 3Com 3CR990 NIC is installed NOTE You may assign any policy to the default device set The No sniffing no spoofing...

Страница 12: ...w frame The NIC should be listed in the default device set 4 If desired remove the temporary directory created for the NIC installation package For information on other installation methods refer to t...

Страница 13: ...indows 2000 Standard rule set you can create a sample policy by following the steps in the section below Creating a Policy In this section you will create a sample policy called the No IP Initiation p...

Страница 14: ...include information about what the policy does or when to use it for example the bulleted information provided at the beginning of this section 6 The access control list ACL initially contains only t...

Страница 15: ...evious section A device set is a collection of EFW devices that are associated with a specific policy You can define any number of device sets and assign EFW devices to any one of those device sets To...

Страница 16: ...ion policy To ensure that the policy is functioning as expected the following steps attempt to connect to the Internet by initiating the TCP protocol HTTP which should be denied by the policy being en...

Страница 17: ...de Expanding Your EFW Configuration Now that you have a basic EFW system configured and running you can expand your configuration as needed to best suit your organization s security needs The followin...

Страница 18: ......

Отзывы: