![AhnLab TrusGuard Скачать руководство пользователя страница 45](http://html.mh-extra.com/html/ahnlab/trusguard/trusguard_installation-manual_2870516045.webp)
3
Chapter3 Installation
45
Traffic Size and Type
Set the traffic processing capacity according to the traffic size, and select an appropriate TrusGuard
device.
Identify Protection Target
Check the network bandwidth and hosts and application services to protect or exclude from
protection.
Sub-network
This information is used to define the IP address of network interface and the IP address profile of sub-
network to be used by TrusGuard.
The bigger the network, the more divided the network should be.
You need the same number of network interface as the sub-network.
Allot at least one IP address for TrusGuard to use in each sub-network.
If there is a sub-network that must use HA mode, allot two IP addresses to each network interface.
External/Internal Service Hosts
Service host information is used to define the IP address profile/group, service profile and IPS policy
profiles.
Main server in each sub-network: IP address of the server that use access control policy
Service provided by the server and users: service provided to outside the network, and service
provided to the sub-network.
Types and versions of OS and applications installed on the server/host: this information is used to
set the IPS policy profile. There are advanced security policies that cannot be applied to hosts using
Linux or Mac OS.These hosts need to be added to the policy exceptions list.
Security Policies
Specify the following security policies.
VPN: VPN policy is needed to ensure intergrity and confidentiality when each physically separated
sub-network communicates via the Internet.
•
IPSec VPN: IPSec VPN is needed for communication between sub-networks.
•
SSL VPN: SSL VPN is needed when the user needs to connect to a sub-network via the Internet.
Time to allow/block connection: Time to operate specific services.
QoS: Check whether traffic shaping is required for specific services.
User Authentication: Specify to allow users registered on TrusGuard only, or allow users registered
on the user authentication server (e.g.: Active Directory, RADIUS, LDAP) only.
Содержание TrusGuard
Страница 1: ......
Страница 15: ...Chapter2 AhnLab TrusGuard Overview Introduction 16 TrusGuard System Specifications 21 Compatibility 40 ...
Страница 104: ...104 AhnLab TrusGuard Installation Guide ...
Страница 105: ...Chapter4 Client Program TrusGuard SSL VPN Client 106 TrusGuard Auth 115 ...
Страница 118: ...118 AhnLab TrusGuard Installation Guide ...
Страница 119: ...Chapter5 Remove Device Remove Device 120 ...