SANGFOR IAM v2.1 User Manual
114
For instance, if you want the LAN users to run applications only based on HTTP protocol, you
need Allow ([Action]) all the HTTP applications ([Type]) and DNS application ([Type]).
<Select All>, <Inverse>: Click the button to quickly select the needed applications.
<Allow>, <Deny>, <Delete>: Click the button to allow or deny or delete the selected
application(s).
<Move Up>, <Move Down>: Click the button to move up or move down the corresponding
selected application(s).
[Default Action]: Select [Allow] or [Deny] to configure the default action of the current access
control policy to the application(s) rules that are not in the above rule list. This item functions in
association with the application(s) configured above.
[If several policies are associated, adopt the default action of the next policy and continue
matching downwards]: If multiple access control policies are associated by a user or user group,
uncheck this item and the [Default Action] of the current policy will be adopted after the data
packets complete matching its rules; or check this item and the data packets will continue to match
the application rules of the access control policies followed.
Having completed the configuration on this page, you have to click the <OK> button to save the
settings.
7.1.2.1.2.
Service Control
[Service Control] configures the destination IP address, port and time schedule of the data packets
based on which certain application will be inspected and controlled.
[Service Control]: You have to check it to activate the rules configured under it, as shown below:
Содержание IAM 2.1
Страница 1: ...SANGFOR IAM v2 1 User Manual IAM 2 1 User Manual September 2010...
Страница 296: ...SANGFOR IAM v2 1 User Manual 295...