About Firewall Rulebases . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 434
Firewall Rules (Zone and Global) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 434
VPN Links and Rules . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 435
About Rule Groups . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 436
About the Multicast Rulebase . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 436
About IDP Rulebases on ISG Family Devices . . . . . . . . . . . . . . . . . . . . . . . . . 436
About IDP Rulebases on Standalone IDP Sensors . . . . . . . . . . . . . . . . . . . . 437
Enabling IPSec Null Encryption for IDP Inspection . . . . . . . . . . . . . . . . . . . . 438
Managing Security Policies . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 438
Creating a Security Policy . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 438
Configuring Objects for Rules . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 439
Applying the Same Object to Multiple Rules . . . . . . . . . . . . . . . . . . . . . 439
Naming of Address Objects in a Security Policy That References Devices
Running ScreenOS or Junos OS . . . . . . . . . . . . . . . . . . . . . . . . . . . 440
Using the Policy Filter Tool . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 440
Filtering the Comment Field . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 440
Using a Predefined IDP Policy . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 440
Using the Policy Creation Wizard . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 441
Adding Rulebases . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 442
Configuring Firewall Rules . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 442
Defining Match for Firewall Rules . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 443
Configuring Source and Destination Zones for Firewall Rules . . . . . . . . 443
Configuring Source and Destination Addresses for Firewall Rules . . . . 444
Support for Any-IPv6 as a Source Address . . . . . . . . . . . . . . . . . . . . . . 445
Configuring Services for Firewall Rules . . . . . . . . . . . . . . . . . . . . . . . . . 446
Defining Actions for Firewall Rules . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 446
Selecting Devices for Firewall Rules . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 447
Configuring Firewall Rule Options . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 448
Enabling NAT . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 448
Enabling GTP for Firewall Rules . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 449
Configuring Traffic Shaping in a Security Policy . . . . . . . . . . . . . . . . . . . 449
Enabling Logging and Counting for Firewall Rules . . . . . . . . . . . . . . . . . 451
Miscellaneous . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 452
ID . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 453
Configuring Web Filtering for Firewall Rules . . . . . . . . . . . . . . . . . . . . . . 454
Configuring Authentication for Firewall Rules . . . . . . . . . . . . . . . . . . . . 455
Configuring Antivirus for Firewall Rules . . . . . . . . . . . . . . . . . . . . . . . . . 456
Configuring a DI Profile/Enable IDP for Firewall Rules . . . . . . . . . . . . . . 457
Limiting Sessions per Policy from Source IPs . . . . . . . . . . . . . . . . . . . . . 458
Configuring the Session Close Notification Rule . . . . . . . . . . . . . . . . . . 458
Comments for Firewall Rules . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 459
Configuring Multicast Rules . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 459
Configuring Source and Destination Zones . . . . . . . . . . . . . . . . . . . . . . . . . . 460
Configuring Source and Destination Groups . . . . . . . . . . . . . . . . . . . . . . . . . 460
Configuring Rule Options . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 460
Configuring Antivirus Rules . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 461
Configuring Antispam Rules . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 462
xxi
Copyright © 2010, Juniper Networks, Inc.
Table of Contents
Содержание NETWORK AND SECURITY MANAGER 2010.3
Страница 6: ...Copyright 2010 Juniper Networks Inc vi...
Страница 36: ...Copyright 2010 Juniper Networks Inc xxxvi Network and Security Manager Administration Guide...
Страница 52: ...Copyright 2010 Juniper Networks Inc 2 Network and Security Manager Administration Guide...
Страница 90: ...Copyright 2010 Juniper Networks Inc 40 Network and Security Manager Administration Guide...
Страница 144: ...Copyright 2010 Juniper Networks Inc 94 Network and Security Manager Administration Guide...
Страница 146: ...Copyright 2010 Juniper Networks Inc 96 Network and Security Manager Administration Guide...
Страница 234: ...Copyright 2010 Juniper Networks Inc 184 Network and Security Manager Administration Guide...
Страница 310: ...Copyright 2010 Juniper Networks Inc 260 Network and Security Manager Administration Guide...
Страница 364: ...Copyright 2010 Juniper Networks Inc 314 Network and Security Manager Administration Guide...
Страница 366: ...Copyright 2010 Juniper Networks Inc 316 Network and Security Manager Administration Guide...
Страница 478: ...Copyright 2010 Juniper Networks Inc 428 Network and Security Manager Administration Guide...
Страница 576: ...Copyright 2010 Juniper Networks Inc 526 Network and Security Manager Administration Guide...
Страница 580: ...Copyright 2010 Juniper Networks Inc 530 Network and Security Manager Administration Guide...
Страница 592: ...Copyright 2010 Juniper Networks Inc 542 Network and Security Manager Administration Guide...
Страница 684: ...Copyright 2010 Juniper Networks Inc 634 Network and Security Manager Administration Guide...
Страница 690: ...Copyright 2010 Juniper Networks Inc 640 Network and Security Manager Administration Guide...
Страница 696: ...Copyright 2010 Juniper Networks Inc 646 Network and Security Manager Administration Guide...
Страница 698: ...Copyright 2010 Juniper Networks Inc 648 Network and Security Manager Administration Guide...
Страница 748: ...Copyright 2010 Juniper Networks Inc 698 Network and Security Manager Administration Guide...
Страница 778: ...Copyright 2010 Juniper Networks Inc 728 Network and Security Manager Administration Guide...
Страница 870: ...Copyright 2010 Juniper Networks Inc 820 Network and Security Manager Administration Guide...
Страница 872: ...Copyright 2010 Juniper Networks Inc 822 Network and Security Manager Administration Guide...
Страница 898: ...Copyright 2010 Juniper Networks Inc 848 Network and Security Manager Administration Guide...
Страница 908: ...Copyright 2010 Juniper Networks Inc 858 Network and Security Manager Administration Guide...
Страница 910: ...Copyright 2010 Juniper Networks Inc 860 Network and Security Manager Administration Guide...
Страница 995: ...PART 6 Index Index on page 947 945 Copyright 2010 Juniper Networks Inc...
Страница 996: ...Copyright 2010 Juniper Networks Inc 946 Network and Security Manager Administration Guide...