P O L I C Y C O N F I G U R A T I O N
Configuring Policies
9-6
Security Appliance User Guide
Version 3R2
9
•
Enable Policy Logging
—Turning policy logging on or off.
•
About Schedules
—Adding day and time schedules for the policy.
E X A M P L E : C R E A T E A P O L I C Y
Allow FTP traffic from the eth1 interface in the untrust zone to a server
with IP address 4.4.4.4 on the eth0 interface in the trust zone:
set address trust FTPtrust 4.4.4.4
set policy from untrust to trust any FTPtrust ftp permit
save
G U I E X A M P L E : C R E A T E A P O L I C Y
1
Objects > Add Address Object
2
Enter the following, then click
Apply
:
Name: FTP Trust
IP Address/Netmask: 4.4.4.4/24
Zone: Trust
3
Policy > Add Policy
4
Enter the following, then click
Apply
:
Location
Action: Permit
Source Zone: Untrust
Destination Zone: Trust
Source Address: Any
Destination Address: FTPTrust
Service: FTP
NAMING POLICIES
Use the
set policy
command with the
name
option to add a name when
you create the policy:
set policy name {name_str} from {src_zone} to {dst_zone}
{src_addr} {dst_addr} {srvc} permit | deny | reject
Содержание freeGuard Blaze 2100
Страница 1: ...freeGuard Blaze 2100 User Guide Version 3R2...
Страница 14: ...I NT R O DU C T I O N About Document Conventions 1 4 Security Appliance User Guide Version 3R2 1...
Страница 24: ...G E T T IN G S T A R T E D Installing the freeGuard Blaze 2100 2 10 Security Appliance User Guide Version 3R2 2...
Страница 82: ...SY ST EM MA N AGEM E N T Using Traceroute 4 22 Security Appliance User Guide Version 3R2 4...
Страница 192: ...P OL IC Y CO NF I G URA T IO N About Schedules 9 28 Security Appliance User Guide Version 3R2 9...
Страница 216: ...P R E DEF I N E D SER V IC ES A 4 Security Appliance User Guide Version 3R2 A...