210
McAfee UTM Firewall 4.0.4 Administration Guide
Firewall menu options
Access control
5
In the Exceptions text box, enter the LAN IP address of the appliance.
6
Click OK in each subsequent dialog box until done.
ACL tab
The ACL (Access Control Lists) enables configuration of allowed and blocked source and destination hosts
using addresses defined on the Addresses page. Access can be blocked or allowed by the source (LAN) IP
address or address range, the Destination (Internet) host’s IP address or address range, or the Destination
Host’s name. The source/destination address of the current network request will be matched against the list
of firewall groups, IP addresses, IP address ranges and host IP address. A successful match allows or blocks
the network request as appropriate. There is no performance hit for increasing the size of an IP address
range and negligible cost for increasing the number of ranges, groups, or hosts.
Note:
All Internet traffic, not just Web traffic, is affected by ACL.
Prerequisites:
• ACLs require previously configured Definitions to allow or deny. Addresses are added through the
Definitions menu. Refer to the
Definitions
for further details.
• Access control must be enabled. See
Enabling access control
.
Configuring ACL
1
From the Firewall menu, click Access control > ACL tab. The Access Control Lists page appears
(
Figure 212
).
Figure 212 ACL tab
2
[Optional] Select allowed source hosts from the Allowed Source Hosts list. The default is None.
Available options Available options depend upon the Addresses defined in the Definitions menu.
3
[Optional] Select blocked source hosts from the Blocked Source Hosts list. The default is None.
Available options Available options depend upon the Addresses defined in the Definitions menu.
4
[Optional] Select allowed destination hosts from the Allowed Destination Hosts list. The default is
None. Available options depend upon the Addresses defined in the Definitions menu.
5
[Optional] Select blocked destination hosts from the Blocked Destination Hosts list. The default is
None. Available options depend upon the Addresses defined in the Definitions menu.
6
Click Submit.
Example ACL: Blocked and allowed hosts
This example defines block rules that stop a range of addresses, with an allow rule that exists as an
exception to the block rules. Since the allow is checked before the block, you can grant access to override
the block rule.
In this scenario, the LAN has an address of 10.0.0.0/24. All source hosts allowed access to the LAN are
number 128 and above, and all source hosts below that range are not allowed access. A block rule for the
range 0-127 prevents access to those source hosts. However, there is an exception to this policy in that a
source host with address 10.0.0.15 requires access. An allow rule can grant access in this circumstance.
Содержание SG310
Страница 1: ...McAfee UTM Firewall Administration Guide version 4 0 4...
Страница 10: ...10 McAfee UTM Firewall 4 0 4 Administration Guide...
Страница 127: ...McAfee UTM Firewall 4 0 4 Administration Guide 127 Network Setup menu options DHCP Server Figure 130 DHCP Addresses page...
Страница 148: ...148 McAfee UTM Firewall 4 0 4 Administration Guide Network Setup menu options SIP...
Страница 238: ...238 McAfee UTM Firewall 4 0 4 Administration Guide Firewall menu options Antispam TrustedSource...
Страница 372: ...372 McAfee UTM Firewall 4 0 4 Administration Guide System menu features Advanced menu...
Страница 410: ...410 McAfee UTM Firewall 4 0 4 Administration Guide Index...
Страница 411: ......
Страница 412: ...700 2237A00...