
SANGFOR IAM v2.1 User Manual
80
[Others] ingress rule can fulfill IP/MAC binding over the layer 3 switch, and ban the client end
from logging into a LAN PC as administrator to access the Internet, which can avoid virus
infection.
The [Others] ingress rule configuration page is as shown below:
Configure [Rule Type], [Rule Name], [Description], etc.
[Options]: Check [Authenticate IP/MAC at the client side] to realize IP/MAC binding over the
layer 3 switch; check [To prevent virus, system file altering and registry altering, deny Internet
access for Admin] to ban the client end from logging in to a LAN PC as administrator to get
access to the Internet.
Having completed configuring this page, you have to click the <OK> button to save the settings
and add the ingress rule to the [Ingress Rule List].
The condition for applying ingress rule to bind IP/MAC is that, the PC and the IAM
gateway device must be at different subnet segments (crossing a layer 3 switch and the MAC
address changed). In addition to the settings configured here, IP/MAC binding must be configured
in [IAM] > [Organization Structure] > [Edit User] page > [Advanced Settings] > [User Attribute].
For details, please refer to Section 7.4.5.1 Edit User.
4.11.
SSL Certificate
[Trusted Root Certificate List] is coherent to [IAM] > [Access Control Policy] > [Edit Access
Control Policy] > [SSL Management] > [SSL Control]. If the [SSL Control] is enabled, then the
Содержание IAM 2.1
Страница 1: ...SANGFOR IAM v2 1 User Manual IAM 2 1 User Manual September 2010...
Страница 296: ...SANGFOR IAM v2 1 User Manual 295...