3.6. IP Rules and IP Policies
3.6.1. Security Policies
Before examining IP rule sets in detail, we will first look at the generic concept of
security policies
to which IP rule sets belong.
Security Policy Filtering
NetDefendOS security policies are configured by the administrator to regulate which traffic can
flow through the NetDefend Firewall and how traffic is examined and changed as it flows. Such
policies are described by the contents of different NetDefendOS
rule sets
. These rule sets share a
uniform means of specifying filtering criteria which determine the type of traffic to which they
will apply. The filtering criteria usually consist of the following:
Source Interface
An Interface or Interface Group where the packet is received
at the NetDefend Firewall. This could also be a VPN tunnel.
Source Network
The network that contains the source IP address of the packet.
This might be a NetDefendOS IP object which could define a
single IP address or range of addresses.
Destination Interface
An Interface or an Interface Group from which the packet
would leave the NetDefend Firewall. This could also be a VPN
tunnel.
Destination Network
The network to which the destination IP address of the packet
belongs. This might be a NetDefendOS IP object which could
define a single IP address or range of addresses.
Service
The protocol type to which the packet belongs. Service objects
define a protocol/port type. Examples are HTTP and ICMP.
Service objects also define any ALG which is to be applied to the
traffic
NetDefendOS provides a large number of predefined service
objects but administrator defined
custom services
can also be
created. Existing service objects can also be collected together
into
service groups
.
See
for more information about this topic.
An important principle to note is that usually all filtering criteria must match a data flow through
NetDefendOS for the rule to be applied. The
Service
filter is particularly useful since it is possible
with this to target only a certain protocol such as HTTP or SMTP.
The NetDefendOS Security Policy Rule Sets
The principle NetDefendOS rule sets that define NetDefendOS security policies, and which use
the filtering parameters described above (networks/interfaces/service), include:
•
IP Rules
IP Rule
objects determine which traffic is permitted to pass through the NetDefend Firewall as
well as determining if the traffic is subject to address translation. The network filter for these
rules can be IPv4 or IPv6 addresses (but not both in a single rule). They are further described
Chapter 3: Fundamentals
228
Содержание NetDefendOS
Страница 30: ...Figure 1 3 Packet Flow Schematic Part III Chapter 1 NetDefendOS Overview 30 ...
Страница 32: ...Chapter 1 NetDefendOS Overview 32 ...
Страница 144: ...Chapter 2 Management and Maintenance 144 ...
Страница 220: ... Enable DHCP passthrough Enable L2 passthrough for non IP protocols 4 Click OK Chapter 3 Fundamentals 220 ...
Страница 267: ... SourceNetwork lannet DestinationInterface any DestinationNetwork all nets 4 Click OK Chapter 3 Fundamentals 267 ...
Страница 284: ...Chapter 3 Fundamentals 284 ...
Страница 360: ...The ospf command options are fully described in the separate NetDefendOS CLI Reference Guide Chapter 4 Routing 360 ...
Страница 392: ...Chapter 4 Routing 392 ...
Страница 396: ...Web Interface 1 Go to Network Ethernet If1 2 Select Enable DHCP 3 Click OK Chapter 5 DHCP Services 396 ...
Страница 419: ... Host 2001 DB8 1 MAC 00 90 12 13 14 15 5 Click OK Chapter 5 DHCP Services 419 ...
Страница 420: ...Chapter 5 DHCP Services 420 ...
Страница 424: ...2 Now enter Name lan_Access Action Expect Interface lan Network lannet 3 Click OK Chapter 6 Security Mechanisms 424 ...
Страница 573: ...Chapter 6 Security Mechanisms 573 ...
Страница 575: ...This section describes and provides examples of configuring NAT and SAT rules Chapter 7 Address Translation 575 ...
Страница 607: ...Chapter 7 Address Translation 607 ...
Страница 666: ...Chapter 8 User Authentication 666 ...
Страница 775: ...Chapter 9 VPN 775 ...
Страница 819: ...Chapter 10 Traffic Management 819 ...
Страница 842: ...Chapter 11 High Availability 842 ...
Страница 866: ...Default Enabled Chapter 13 Advanced Settings 866 ...
Страница 879: ...Chapter 13 Advanced Settings 879 ...